A vulnerability marked as critical has been reported in nextlevelbuilder GoClaw up to 3.13.2. Affected by this issue is the function
ToolsInvokeHandler.ServeHTTP of the file internal/http/tools_invoke.go of the component Invoke Endpoint. This manipulation causes missing authorization.
This vulnerability is handled as CVE-2026-16123. The attack can be initiated remotely. Additionally, an exploit exists.