PT-2026-60996 · Sipeed · Picoclaw

·

CVE-2026-16197

·

Published

2026-07-18

·

Updated

2026-07-18

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Sipeed PicoClaw versions prior to 0.3.0
Description An issue in the Group Message Handler component allows for missing authorization. This occurs within the handleMessageReceive() function located in the pkg/channels/feishu/feishu 64.go file. The flaw can be exploited remotely.
Recommendations Update Sipeed PicoClaw to version 0.3.0 or later. As a temporary mitigation, restrict access to the handleMessageReceive() function.

Exploit

Fix

Incorrect Authorization

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16197

Affected Products

Picoclaw