CVE-2026-15629

Source
https://cve.org/CVERecord?id=CVE-2026-15629
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-15629.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-15629
Published
2026-07-14T03:30:09.462Z
Modified
2026-07-16T03:47:31.934862542Z
Severity
  • 2.1 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
louisho5 picobot Workspace filesystem.go GetSkill link following
Details

A weakness has been identified in louisho5 picobot up to 0.2.0. Impacted is the function CreateSkill/GetSkill of the file internal/agent/tools/filesystem.go of the component Workspace Handler. Executing a manipulation can lead to link following. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

Database specific
{
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "introduced": "0.1"
                },
                {
                    "last_affected": "0.1"
                }
            ]
        }
    ],
    "cna_assigner": "VulDB",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/15xxx/CVE-2026-15629.json",
    "cwe_ids": [
        "CWE-59"
    ]
}
References

Affected packages

Git / github.com/louisho5/picobot

Affected ranges

Type
GIT
Repo
https://github.com/louisho5/picobot
Events
Database specific
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "0.2.0"
        },
        {
            "last_affected": "0.2.0"
        }
    ]
}

Affected versions

0.*
0.2.0
v0.*
v0.2.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-15629.json"