CVE-2026-15624: Nextlevelbuilder Goclaw
Medium severity, CVSS 6.3. EPSS: 0.4% chance of exploitation in the next 30 days.
A vulnerability has been found in nextlevelbuilder GoClaw 3.13.3-beta.3. Affected by this vulnerability is the function bytePlusDownloadVideo of the file internal/tools/create_video_byteplus.go of the component invoke Endpoint. The manipulation of the argument output.video_url leads to server-side request forgery. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
Affected products
- Nextlevelbuilder Goclaw: version 3.13.3-beta.3 only
Published 2026-07-14. Last modified 2026-07-15.