CVE-2026-16085

Source
https://cve.org/CVERecord?id=CVE-2026-16085
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-16085.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-16085
Published
2026-07-18T09:15:09Z
Modified
2026-08-12T03:51:10Z
Severity
  • 1.9 (Low) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
Sipeed PicoClaw context.go NewContextBuilder inclusion of functionality from untrusted control sphere
Details

A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. Affected is the function NewContextBuilder of the file pkg/agent/context.go. Such manipulation leads to inclusion of functionality from untrusted control sphere. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. The reported GitHub issue was closed automatically with the label "not planned" by a bot.

Database specific
{
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-829"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/16xxx/CVE-2026-16085.json"
}
References

Affected packages

Git / github.com/sipeed/picoclaw

Affected ranges

Type
GIT
Repo
https://github.com/sipeed/picoclaw
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0.2.0"
        },
        {
            "last_affected": "0.2.0"
        },
        {
            "introduced": "0.2.1"
        },
        {
            "last_affected": "0.2.1"
        },
        {
            "introduced": "0.2.2"
        },
        {
            "last_affected": "0.2.2"
        },
        {
            "introduced": "0.2.3"
        },
        {
            "last_affected": "0.2.3"
        },
        {
            "introduced": "0.2.4"
        },
        {
            "last_affected": "0.2.4"
        },
        {
            "introduced": "0.2.5"
        },
        {
            "last_affected": "0.2.5"
        },
        {
            "introduced": "0.2.6"
        },
        {
            "last_affected": "0.2.6"
        },
        {
            "introduced": "0.2.7"
        },
        {
            "last_affected": "0.2.7"
        },
        {
            "introduced": "0.2.8"
        },
        {
            "last_affected": "0.2.8"
        },
        {
            "introduced": "0.2.9"
        },
        {
            "last_affected": "0.2.9"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

0.*
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
v0.*
v0.2.0
v0.2.1
v0.2.2
v0.2.2-nightly.20260312.6612ca09
v0.2.3
v0.2.4
v0.2.5
v0.2.6
v0.2.7
v0.2.8
v0.2.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-16085.json"