PT-2026-57949 · Git+1 · Poco-Claw
CVSS v4.0
5.5
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P |
Name of the Vulnerable Software and Affected Versions
poco-ai poco-claw versions prior to 0.5.5
Description
A flaw in the Workspace API component allows a remote attacker to bypass authorization. The issue exists in the
get workspace file() function within the file executor manager/app/api/v1/workspace.py. By manipulating the user id variable, an attacker can gain unauthorized access.Recommendations
Update poco-ai poco-claw to version 0.5.5 or later.
As a temporary mitigation, restrict access to the
user id parameter in the affected API endpoint.Exploit
Fix
IDOR
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Poco-Claw