Unrated severityNVD Advisory· Published Jul 10, 2026· Updated Jul 14, 2026
Sipeed PicoClaw Guarded Web Fetch Flow web.go WebFetchTool.Execute server-side request forgery
CVE-2026-15317
Description
A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. Affected by this vulnerability is the function WebFetchTool.Execute of the file pkg/tools/integration/web.go of the component Guarded Web Fetch Flow. The manipulation results in server-side request forgery. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. The reported GitHub issue was closed automatically due to inactivity.
Affected products
1Patches
Vulnerability mechanics
References
5- github.com/sipeed/picoclaw/issues/3078mitreexploitissue-tracking
- vuldb.com/cve/CVE-2026-15317mitrethird-party-advisory
- vuldb.com/submit/852877mitrethird-party-advisory
- vuldb.com/vuln/377257mitrevdb-entrytechnical-description
- vuldb.com/vuln/377257/ctimitresignaturepermissions-required
News mentions
0No linked articles in our index yet.