PT-2026-45821 · Goclaw · Goclaw
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
GoClaw versions prior to 3.11.4
Description
An issue in the Webhook Verification Handler component allows for missing authentication. This occurs within the
resolveAuth() function located in the internal/http/auth.go file, enabling remote exploitation.Recommendations
Update to version 3.11.4 or later.
As a temporary workaround, restrict access to the
resolveAuth() function in the Webhook Verification Handler.Exploit
Fix
Missing Authentication
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Goclaw