Louisho5 · Picobot · CVE-2026-15669
**Name of the Vulnerable Software and Affected Versions**
louisho5 picobot versions prior to 0.2.1
**Description**
An OS command injection issue exists within the `ExecTool.Execute()` function located in the `internal/agent/tools/exec.go` file of the exec Tool component. This flaw allows for the execution of arbitrary operating system commands, though it requires a local approach to exploit.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary mitigation, restrict access to the `ExecTool.Execute()` function.