High severity7.3NVD Advisory· Published May 27, 2026· Updated Jun 17, 2026
CVE-2026-36045
CVE-2026-36045
Description
picoclaw <=v0.1.2 and earlier is vulnerable to OS command injection via the ExecTool component (pkg/tools/shell.go). The guardCommand() function attempts to restrict shell command execution using a denylist of 8 regular expressions, but the denylist is incomplete.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/sipeed/picoclawGo | <= 0.1.2 | — |
Affected products
2- osv-coordsRange: < 0.0.20260723T184607-160000.1.1
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-cv2p-68f4-f4pwghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-36045ghsaADVISORY
- gist.github.com/NucleiAv/41899be6266a9813840301577792ed68nvdWEB
- github.com/sipeed/picoclaw/commit/01d694b9985a66c3d7119fc9f74ce8ed4f0f21b5ghsaWEB
- github.com/sipeed/picoclaw/releases/tag/v0.1.2nvdWEB
News mentions
0No linked articles in our index yet.