A vulnerability was identified in Sipeed PicoClaw up to 0.2.9. The impacted element is the function ExecTool.executeRun of the file pkg/agent/pipeline_execute.go. The manipulation of the argument cwe leads to time-of-check time-of-use. The attack must be carried out locally. The exploit is publicly available and might be used. The reported GitHub issue was closed automatically with the label "not planned" by a bot.
{
"cna_assigner": "VulDB",
"cwe_ids": [
"CWE-362",
"CWE-367"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/16xxx/CVE-2026-16082.json"
}{
"extracted_events": [
{
"introduced": "0.2.0"
},
{
"last_affected": "0.2.0"
},
{
"introduced": "0.2.1"
},
{
"last_affected": "0.2.1"
},
{
"introduced": "0.2.2"
},
{
"last_affected": "0.2.2"
},
{
"introduced": "0.2.3"
},
{
"last_affected": "0.2.3"
},
{
"introduced": "0.2.4"
},
{
"last_affected": "0.2.4"
},
{
"introduced": "0.2.5"
},
{
"last_affected": "0.2.5"
},
{
"introduced": "0.2.6"
},
{
"last_affected": "0.2.6"
},
{
"introduced": "0.2.7"
},
{
"last_affected": "0.2.7"
},
{
"introduced": "0.2.8"
},
{
"last_affected": "0.2.8"
},
{
"introduced": "0.2.9"
},
{
"last_affected": "0.2.9"
}
],
"source": "AFFECTED_FIELD"
}