PT-2026-57046 · Sipeed · Picoclaw
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Sipeed PicoClaw versions prior to 0.3.0
Description
Improper access controls exist within the Launcher component, specifically affecting the
IPAllowlist() function located in the web/backend/middleware/access control.go file. This flaw allows a remote attacker to manipulate access controls.Recommendations
Apply patch 3126 to resolve the issue.
As a temporary mitigation, restrict access to the
IPAllowlist() function until the patch is applied.Exploit
Fix
Incorrect Privilege Assignment
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Picoclaw