PT-2026-45820 · Goclaw · Goclaw
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
GoClaw versions prior to 3.11.4
Description
A weakness in the Team Task Completion Handler component allows for missing authorization. This issue occurs within the
TeamTasksTool.executeComplete() function located in the internal/tools/team tasks lifecycle.go file. A remote attacker can exploit this flaw by executing a manipulation to bypass authorization controls.Recommendations
Update to version 3.11.4 or later.
As a temporary workaround, restrict access to the
TeamTasksTool.executeComplete() function until the update is applied.Exploit
Fix
Missing Authorization
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Goclaw