Impact
A flaw exists in the ExecTool.Execute function of Picobot. An attacker who can provide crafted input to this function can cause the program to invoke arbitrary operating‑system commands. The vulnerability maps to CWE‑77 and CWE‑78. The effect is that a local user with access to the exec tool can run commands with the user’s privileges, potentially compromising system integrity and confidentiality.
Affected Systems
The affected product is Louisho5 Picobot up to and including version 0.2.0. No official patch has been released by the developer, and the project has not addressed the issue yet.
Risk and Exploitability
The CVSS score of 4.8 indicates low severity. The EPSS score is below 1%, suggesting a very low probability of widespread exploitation, but the public availability of an exploit means that the risk is not negligible for local users. This vulnerability is not listed in the CISA KEV catalog, so no additional mitigation guidance is available from that source. Because execution is local, an attacker who can influence the ExecTool.Execute input can run arbitrary OS commands with the application’s privileges.
OpenCVE Enrichment