CVE-2026-15624

A vulnerability has been found in nextlevelbuilder GoClaw 3.13.3-beta.3. Affected by this vulnerability is the function bytePlusDownloadVideo of the file internal/tools/create_video_byteplus.go of the component invoke Endpoint. The manipulation of the argument output.video_url leads to server-side request forgery. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
Configurations

No configuration.

History

15 Jul 2026, 16:16

Type Values Removed Values Added
References () https://vuldb.com/submit/855798 - () https://vuldb.com/submit/855798 -

14 Jul 2026, 02:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-14 02:16

Updated : 2026-07-15 16:16


NVD link : CVE-2026-15624

Mitre link : CVE-2026-15624

CVE.ORG link : CVE-2026-15624


JSON object : View

Products Affected

No product.

CWE
CWE-918

Server-Side Request Forgery (SSRF)