PT-2026-45820 · Goclaw · Goclaw

·

CVE-2026-10616

·

Published

2026-06-02

·

Updated

2026-06-04

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions GoClaw versions prior to 3.11.4
Description A weakness in the Team Task Completion Handler component allows for missing authorization. This issue occurs within the TeamTasksTool.executeComplete() function located in the internal/tools/team tasks lifecycle.go file. A remote attacker can exploit this flaw by executing a manipulation to bypass authorization controls.
Recommendations Update to version 3.11.4 or later. As a temporary workaround, restrict access to the TeamTasksTool.executeComplete() function until the update is applied.

Exploit

Fix

Missing Authorization

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-10616

Affected Products

Goclaw