GHSA-49hh-3wxf-qhw8LowCVSS 5.3

A vulnerability was identified in Sipeed PicoClaw up to 0.2.9. The impacted element is the...

Published
July 18, 2026
Last Modified
July 18, 2026

🔗 CVE IDs covered (1)

📋 Description

A vulnerability was identified in Sipeed PicoClaw up to 0.2.9. The impacted element is the function ExecTool.executeRun of the file pkg/agent/pipeline_execute.go. The manipulation of the argument cwe leads to time-of-check time-of-use. The attack must be carried out locally. The exploit is publicly available and might be used. The reported GitHub issue was closed automatically with the label "not planned" by a bot.

🔗 References (8)