CVE-2026-15624: Nextlevelbuilder Goclaw

Medium severity, CVSS 6.3. EPSS: 0.4% chance of exploitation in the next 30 days.

A vulnerability has been found in nextlevelbuilder GoClaw 3.13.3-beta.3. Affected by this vulnerability is the function bytePlusDownloadVideo of the file internal/tools/create_video_byteplus.go of the component invoke Endpoint. The manipulation of the argument output.video_url leads to server-side request forgery. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.

Affected products

Published 2026-07-14. Last modified 2026-07-15.