Impact
The vulnerability resides in Louisho5 Picobot up to version 0.2.0, within the WebTool.Execute function. An attacker can supply a crafted URL argument that is passed directly to an internal request‑making routine, enabling the tool to make arbitrary outbound HTTP requests. This server‑side request forgery can be exploited remotely to reach internal resources or exfiltrate data.
Affected Systems
The affected product is Louisho5 Picobot, any instance running version 0.2.0 or older. The issue is present in the web tool component of the internal agent tools. No vendor patch exists yet; the project has not responded to issue reports.
Risk and Exploitability
The CVSS score is 5.3, indicating a moderate severity. The EPSS score is < 1%, reflecting a low but nonzero exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The exploitation requires the victim to invoke the web service endpoint that calls WebTool.Execute with a malicious URL. It is not explicitly stated that additional compromise is needed, so this is inferred. Because the SSRF can target internal network services, the risk is significant if the attacker can reach privileged endpoints.
OpenCVE Enrichment