CVE-2026-16016

Source
https://cve.org/CVERecord?id=CVE-2026-16016
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-16016.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-16016
Published
2026-07-17T13:30:10.299Z
Modified
2026-07-19T03:46:27.981209574Z
Severity
  • 5.5 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
poco-ai poco-claw task.py run_task server-side request forgery
Details

A vulnerability was identified in poco-ai poco-claw up to 0.5.4. This issue affects the function runtask of the file executor/app/api/v1/task.py. The manipulation of the argument callbackurl leads to server-side request forgery. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The reported GitHub issue was closed automatically due to inactivity.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/16xxx/CVE-2026-16016.json",
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-918"
    ]
}
References

Affected packages

Git / github.com/poco-ai/poco-claw

Affected ranges

Type
GIT
Repo
https://github.com/poco-ai/poco-claw
Events
Database specific
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "0.5.0"
        },
        {
            "last_affected": "0.5.0"
        },
        {
            "introduced": "0.5.1"
        },
        {
            "last_affected": "0.5.1"
        },
        {
            "introduced": "0.5.2"
        },
        {
            "last_affected": "0.5.2"
        },
        {
            "introduced": "0.5.3"
        },
        {
            "last_affected": "0.5.3"
        },
        {
            "introduced": "0.5.4"
        },
        {
            "last_affected": "0.5.4"
        }
    ]
}

Affected versions

0.*
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
v0.*
v0.5.0
v0.5.1
v0.5.2
v0.5.3
v0.5.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-16016.json"