A vulnerability categorized as critical has been discovered in nextlevelbuilder GoClaw up to 3.13.3-beta.3. This impacts the function
matchesAllowlist/extractBin of the file internal/tools/exec_approval.go. Executing a manipulation can lead to incorrectly-resolved name.
This vulnerability appears as CVE-2026-16120. The attack may be performed from remote. In addition, an exploit is available.