PT-2026-43703 · Picoclaw · Picoclaw

·

CVE-2026-36045

·

Published

2026-05-27

·

Updated

2026-07-30

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions picoclaw versions prior to 0.1.3
Description The ExecTool component (pkg/tools/shell.go) allows OS command injection. This occurs because the guardCommand() function uses an incomplete denylist of eight regular expressions to restrict shell command execution, failing to block all malicious inputs.
Recommendations Update picoclaw to a version later than 0.1.2. As a temporary workaround, restrict the use of the guardCommand() function within the ExecTool component.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-36045
GHSA-CV2P-68F4-F4PW
GO-2026-5867
OPENSUSE-SU-2026:21483-1

Affected Products

Picoclaw