PT-2026-60996 · Sipeed · Picoclaw
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Sipeed PicoClaw versions prior to 0.3.0
Description
An issue in the Group Message Handler component allows for missing authorization. This occurs within the
handleMessageReceive() function located in the pkg/channels/feishu/feishu 64.go file. The flaw can be exploited remotely.Recommendations
Update Sipeed PicoClaw to version 0.3.0 or later.
As a temporary mitigation, restrict access to the
handleMessageReceive() function.Exploit
Fix
Incorrect Authorization
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Picoclaw