Description
A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. The affected element is the function handleMessageReceive of the file pkg/channels/feishu/feishu_64.go of the component Group Message Handler. Such manipulation leads to missing authorization. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The reported GitHub issue was closed automatically due to inactivity.
Published: 2026-07-18
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability occurs when the handleMessageReceive function in feishu_64.go does not enforce proper authorization checks. An attacker can manipulate the input sent to this function to bypass those checks, thereby gaining unauthorized access to the Group Message Handler. This allows the attacker to read, modify, or delete group messages, resulting in confidentiality and integrity violations within the messaging system.

Affected Systems

All Sipeed PicoClaw firmware releases up to 0.2.9 are affected. The flaw resides in the Group Message Handler component of the feishu module. Any deployment of PicoClaw that includes this component is susceptible to exploitation.

Risk and Exploitability

The CVSS score of 5.3 points to medium severity, while the EPSS score of less than 1% indicates a very low predicted probability of exploitation. The vulnerability is not listed in CISA's KEV catalog. The exploit is remote, requiring network access to the message handling endpoint, and can be executed by an attacker who sends crafted data to the vulnerable function.

Generated by OpenCVE AI on July 30, 2026 at 22:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest PicoClaw firmware that resolves the missing authorization bug
  • If an updated firmware is not yet available, block external traffic to the Group Message Handler API using firewalls or network segmentation
  • Continuously monitor system logs and audit trails for unauthorized attempts to invoke the handleMessageReceive endpoint

Generated by OpenCVE AI on July 30, 2026 at 22:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 20 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 18 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. The affected element is the function handleMessageReceive of the file pkg/channels/feishu/feishu_64.go of the component Group Message Handler. Such manipulation leads to missing authorization. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The reported GitHub issue was closed automatically due to inactivity.
Title Sipeed PicoClaw Group Message feishu_64.go handleMessageReceive authorization
First Time appeared Sipeed
Sipeed picoclaw
Weaknesses CWE-862
CWE-863
CPEs cpe:2.3:a:sipeed:picoclaw:*:*:*:*:*:*:*:*
Vendors & Products Sipeed
Sipeed picoclaw
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-07-20T19:11:06.535Z

Reserved: 2026-07-18T07:22:36.968Z

Link: CVE-2026-16197

cve-icon Vulnrichment

Updated: 2026-07-20T19:10:58.362Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T23:00:22Z

Weaknesses