picoclaw <=v0.1.2 and earlier is vulnerable to OS command injection via the ExecTool component (pkg/tools/shell.go). The guardCommand() function attempts to restrict shell command execution using a denylist of 8 regular expressions, but the denylist is incomplete.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 27 May 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | OS Command Injection in picoclaw’s ExecTool Component due to Incomplete Denylist | |
| First Time appeared |
Sipeed
Sipeed picoclaw |
|
| Weaknesses | CWE-78 | |
| Vendors & Products |
Sipeed
Sipeed picoclaw |
Wed, 27 May 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | picoclaw <=v0.1.2 and earlier is vulnerable to OS command injection via the ExecTool component (pkg/tools/shell.go). The guardCommand() function attempts to restrict shell command execution using a denylist of 8 regular expressions, but the denylist is incomplete. | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-05-27T13:50:13.849Z
Reserved: 2026-04-06T00:00:00.000Z
Link: CVE-2026-36045
No data.
Status : Received
Published: 2026-05-27T14:16:45.287
Modified: 2026-05-27T14:16:45.287
Link: CVE-2026-36045
No data.
OpenCVE Enrichment
Updated: 2026-05-27T16:00:08Z
Weaknesses