PT-2026-57020 · Sipeed · Picoclaw
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Sipeed PicoClaw versions prior to 0.3.0
Description
A security flaw in the Guarded Web Fetch Flow component allows for remote server-side request forgery (SSRF), a condition where an attacker can induce the server to make requests to an unintended location. The issue resides in the
WebFetchTool.Execute() function within the pkg/tools/integration/web.go file.Recommendations
Update to a version newer than 0.2.9.
As a temporary workaround, restrict access to the
WebFetchTool.Execute() function to minimize the risk of exploitation.Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Picoclaw