Impact
In Sipeed PicoClaw up to version 0.2.9 the function ExecTool.executeRun in pkg/agent/pipeline_execute.go processes an input argument named cwe. An attacker able to modify the value of this argument can induce a race condition where the value is checked before it is used, creating a classic TOCTOU flaw. The vulnerability is local only and does not give an attacker remote access, but it does allow a local user to influence command execution or related logic in a way that bypasses intended controls.
Affected Systems
All releases of Sipeed PicoClaw up to and including 0.2.9 are affected. The flaw resides in the agent component of PicoClaw, specifically within the pipeline_execute.go file.
Risk and Exploitability
The CVSS score of 4.8 classifies the issue as low severity, and the EPSS score of less than 1% suggests a low likelihood of widespread exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploits are publicly available and the flaw can be leveraged by anyone who has local privileges or control over the affected system.
OpenCVE Enrichment