Picoclaw
This hub aggregates every CVE we track for Picoclaw, a product in the ai ml space. Use it to gauge the current risk picture and drill into individual advisories.
14
CVEs tracked
0
Critical
3
High
0
In CISA KEV
Severity distribution
MEDIUM11HIGH3
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
0
13
2024-082026-07
Latest CVEs
The 14 most recently published vulnerabilities affecting Picoclaw.
- CVE-2026-16198Sipeed PicoClaw First Run Setup access_control.go authentication bypass5.6
- CVE-2026-16197Sipeed PicoClaw Group Message feishu_64.go handleMessageReceive authorization6.3
- CVE-2026-16196Sipeed PicoClaw web_fetch web.go isPrivateOrRestrictedIP server-side request forgery6.3
- CVE-2026-16195Sipeed PicoClaw Group Message wecom.go dispatchIncoming authorization6.3
- CVE-2026-16085Sipeed PicoClaw context.go NewContextBuilder inclusion of functionality from untrusted control sphere5.3
- CVE-2026-16084Sipeed PicoClaw web.go web_fetch server-side request forgery7.3
- CVE-2026-16083Sipeed PicoClaw LINE Webhook line.go webhook.ParseRequest authentication replay5.3
- CVE-2026-16082Sipeed PicoClaw pipeline_execute.go ExecTool.executeRun toctou5.3
- CVE-2026-16081Sipeed PicoClaw auth.go cross-site request forgery4.3
- CVE-2026-15320Sipeed PicoClaw pico.go rt.ReloadConfig authorization5.4
- CVE-2026-15319Sipeed PicoClaw Launcher access_control.go IPAllowlist access control7.3
- CVE-2026-15318Sipeed PicoClaw MQTT Channel mqtt.go authorization6.3
- CVE-2026-15317Sipeed PicoClaw Guarded Web Fetch Flow web.go WebFetchTool.Execute server-side request forgery6.3
- CVE-2026-6987PicoClaw Web Launcher Management Plane restart command injection7.3
Product normalization is registry-driven with AI assist and human review. How it works