PT-2026-57020 · Sipeed · Picoclaw

·

CVE-2026-15317

·

Published

2026-07-10

·

Updated

2026-07-10

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Sipeed PicoClaw versions prior to 0.3.0
Description A security flaw in the Guarded Web Fetch Flow component allows for remote server-side request forgery (SSRF), a condition where an attacker can induce the server to make requests to an unintended location. The issue resides in the WebFetchTool.Execute() function within the pkg/tools/integration/web.go file.
Recommendations Update to a version newer than 0.2.9. As a temporary workaround, restrict access to the WebFetchTool.Execute() function to minimize the risk of exploitation.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15317

Affected Products

Picoclaw