PT-2026-57949 · Git+1 · Poco-Claw

·

CVE-2026-15622

·

Published

2026-07-14

·

Updated

2026-07-14

CVSS v4.0

5.5

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P
Name of the Vulnerable Software and Affected Versions poco-ai poco-claw versions prior to 0.5.5
Description A flaw in the Workspace API component allows a remote attacker to bypass authorization. The issue exists in the get workspace file() function within the file executor manager/app/api/v1/workspace.py. By manipulating the user id variable, an attacker can gain unauthorized access.
Recommendations Update poco-ai poco-claw to version 0.5.5 or later. As a temporary mitigation, restrict access to the user id parameter in the affected API endpoint.

Exploit

Fix

IDOR

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15622

Affected Products

Poco-Claw