VYPR
Unrated severityOSV Advisory· Published Jul 18, 2026· Updated Jul 20, 2026

Sipeed PicoClaw auth.go cross-site request forgery

CVE-2026-16081

Description

A vulnerability was determined in Sipeed PicoClaw up to 0.2.9. The affected element is an unknown function of the file web/backend/api/auth.go. Executing a manipulation can lead to cross-site request forgery. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. This patch is called 4b0229351678f479429b8d8b19207757266f246b. Applying a patch is advised to resolve this issue.

Affected products

2
  • Sipeed/PicoclawOSV2 versions
    0.2.0, 0.2.1, 0.2.2, …+ 1 more
    • (no CPE)range: 0.2.0, 0.2.1, 0.2.2, …
    • (no CPE)range: <=0.2.9

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.