PT-2026-60750 · Poco-Claw · Poco-Claw
CVSS v3.1
6.3
Medium
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
poco-ai poco-claw versions prior to 0.5.7
Description
A flaw in the executor manager API component allows for missing authentication. This occurs within the
create task() function located in the executor manager/app/api/v1/tasks.py file. An attacker can perform a manipulation to bypass authentication requirements.Recommendations
Upgrade to version 0.5.7.
As a temporary mitigation, restrict access to the
create task() function in the executor manager/app/api/v1/tasks.py file.Exploit
Fix
Missing Authentication
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Poco-Claw