Impact
The vulnerability exists in poco‑ai poco‑claw versions up to 0.5.4. The run_task function accepts a callback_url argument that is not validated. An attacker can supply an arbitrary URL, causing the server to perform a request to that URL. This leads to server‑side request forgery and can result in disclosure of internal resources or denial of service depending on the target of the SSRF.
Affected Systems
The affected product is poco‑ai poco‑claw. All releases up to and including 0.5.4 are vulnerable. Later releases are not listed as affected. No specific sub‑sub versions are enumerated, so any deployment of poco‑claw 0.5.4 or earlier is considered at risk.
Risk and Exploitability
The CVSS base score for this issue is 6.9, indicating a moderate severity. The EPSS score is less than 1%, suggesting that exploitation probability is low but not zero. The vulnerability is not listed in the CISA KEV catalog. Attackers can trigger the flaw remotely by sending a crafted request to the run_task endpoint with a malicious callback_url. Publicly available proof‑of‑concept code exists, so a ready‑made exploit could be used.
OpenCVE Enrichment