Impact
The flaw resides in the NewContextBuilder function of Sipeed PicoClaw, which unintentionally incorporates functionality from an untrusted control sphere. By manipulating the context builder locally, an attacker can inject arbitrary, privileged functionality into the agent, potentially executing code with elevated rights. The effect is a local privilege escalation within the environment where PicoClaw runs.
Affected Systems
Sipeed PicoClaw versions up to and including 0.2.9 are susceptible to this vulnerability. No newer releases have been identified as affected by the information supplied.
Risk and Exploitability
The CVSS score of 4.8 categorises the issue as moderate, while an EPSS score of less than 1% indicates a very low probability of wide‑scale exploitation. The vulnerability is not listed in the CISA KEV catalogue. Exploitation requires local access, making the attack surface limited to those with physical or administrative access to the device; nevertheless, the potential for privilege escalation warrants prompt attention.
OpenCVE Enrichment