A vulnerability, which was classified as problematic, was found in nextlevelbuilder GoClaw up to 3.13.2. Affected by this vulnerability is the function ExecTool.Execute of the file goclaw/internal/http/tools_invoke.go of the component jq Handler. Executing a manipulation can lead to information disclosure.

This vulnerability is tracked as CVE-2026-18038. The attack can be launched remotely. Moreover, an exploit is present.

It is advisable to implement a patch to correct this issue.