VYPR
Vendor

Sipeed

Products
4
CVEs
16
Across products
16
Status
Private

Products

4

Recent CVEs

16
  • CVE-2026-32296HigMar 17, 2026
    risk 0.46cvss 8.2epss 0.01

    Sipeed NanoKVM before 2.3.1 exposes a Wi-Fi configuration endpoint without proper security checks, allowing an unauthenticated attacker with network access to change the saved configured Wi-Fi network to one of the attacker's choosing, or craft a request to exhaust the system…

  • CVE-2026-36045HigMay 27, 2026
    risk 0.41cvss 7.3epss 0.01

    picoclaw <=v0.1.2 and earlier is vulnerable to OS command injection via the ExecTool component (pkg/tools/shell.go). The guardCommand() function attempts to restrict shell command execution using a denylist of 8 regular expressions, but the denylist is incomplete.

  • CVE-2026-6987HigApr 25, 2026
    risk 0.41cvss 7.3epss 0.03

    A vulnerability was detected in PicoClaw up to 0.2.4. Impacted is an unknown function of the file /api/gateway/restart of the component Web Launcher Management Plane. Performing a manipulation results in command injection. It is possible to initiate the attack remotely. The…

  • CVE-2026-16198MedJul 19, 2026
    risk 0.00cvss 5.6epss 0.00

    A vulnerability was detected in Sipeed PicoClaw up to 0.2.9. The impacted element is an unknown function of the file web/backend/middleware/access_control.go of the component First Run Setup. Performing a manipulation of the argument allowed_cidrs results in authentication…

  • CVE-2026-16197MedJul 18, 2026
    risk 0.00cvss 6.3epss 0.00

    A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. The affected element is the function handleMessageReceive of the file pkg/channels/feishu/feishu_64.go of the component Group Message Handler. Such manipulation leads to missing authorization. The attack…

  • CVE-2026-16196MedJul 18, 2026
    risk 0.00cvss 6.3epss 0.00

    A weakness has been identified in Sipeed PicoClaw up to 0.2.9. Impacted is the function isPrivateOrRestrictedIP of the file pkg/tools/integration/web.go of the component web_fetch. This manipulation causes server-side request forgery. The attack can be initiated remotely. The…

  • CVE-2026-16195MedJul 18, 2026
    risk 0.00cvss 6.3epss 0.00

    A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. This issue affects the function dispatchIncoming of the file pkg/channels/wecom/wecom.go of the component Group Message Handler. The manipulation results in incorrect authorization. It is possible to launch the…

  • CVE-2026-16085MedJul 18, 2026
    risk 0.00cvss 5.3epss 0.00

    A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. Affected is the function NewContextBuilder of the file pkg/agent/context.go. Such manipulation leads to inclusion of functionality from untrusted control sphere. The attack needs to be performed locally.…

  • CVE-2026-16084HigJul 18, 2026
    risk 0.00cvss 7.3epss 0.00

    A weakness has been identified in Sipeed PicoClaw up to 0.2.9. This impacts the function web_fetch of the file pkg/tools/integration/web.go. This manipulation causes server-side request forgery. Remote exploitation of the attack is possible. The exploit has been made available…

  • CVE-2026-16083MedJul 18, 2026
    risk 0.00cvss 5.3epss 0.00

    A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. This affects the function webhook.ParseRequest of the file pkg/channels/line/line.go of the component LINE Webhook. The manipulation results in authentication bypass by capture-replay. The attack may be launched…

  • CVE-2026-16082MedJul 18, 2026
    risk 0.00cvss 5.3epss 0.00

    A vulnerability was identified in Sipeed PicoClaw up to 0.2.9. The impacted element is the function ExecTool.executeRun of the file pkg/agent/pipeline_execute.go. The manipulation of the argument cwe leads to time-of-check time-of-use. The attack must be carried out locally. The…

  • CVE-2026-16081MedJul 18, 2026
    risk 0.00cvss 4.3epss 0.00

    A vulnerability was determined in Sipeed PicoClaw up to 0.2.9. The affected element is an unknown function of the file web/backend/api/auth.go. Executing a manipulation can lead to cross-site request forgery. The attack can be launched remotely. The exploit has been publicly…

  • CVE-2026-15320MedJul 10, 2026
    risk 0.00cvss 5.4epss 0.00

    A vulnerability was detected in Sipeed PicoClaw up to 0.2.9. This vulnerability affects the function rt.ReloadConfig of the file pkg/channels/pico/pico.go. Performing a manipulation of the argument message.send results in missing authorization. It is possible to initiate the…

  • CVE-2026-15319HigJul 10, 2026
    risk 0.00cvss 7.3epss 0.00

    A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. This affects the function IPAllowlist of the file web/backend/middleware/access_control.go of the component Launcher. Such manipulation leads to improper access controls. The attack may be performed from…

  • CVE-2026-15318MedJul 10, 2026
    risk 0.00cvss 6.3epss 0.00

    A weakness has been identified in Sipeed PicoClaw up to 0.2.9. Affected by this issue is some unknown functionality of the file pkg/channels/mqtt/mqtt.go of the component MQTT Channel Handler. This manipulation of the argument client_id causes incorrect authorization. The attack…

  • CVE-2026-15317MedJul 10, 2026
    risk 0.00cvss 6.3epss 0.00

    A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. Affected by this vulnerability is the function WebFetchTool.Execute of the file pkg/tools/integration/web.go of the component Guarded Web Fetch Flow. The manipulation results in server-side request forgery. The…