{"id":"GHSA-cv2p-68f4-f4pw","summary":"picoclaw is vulnerable to OS command injection via the ExecTool component","details":"picoclaw \u003c=v0.1.2 and earlier is vulnerable to OS command injection via the ExecTool component (pkg/tools/shell.go). The guardCommand() function attempts to restrict shell command execution using a denylist of 8 regular expressions, but the denylist is incomplete.","aliases":["CVE-2026-36045","GO-2026-5867"],"modified":"2026-07-07T16:11:25.692196710Z","published":"2026-05-27T15:33:11Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-07-01T19:06:33Z","nvd_published_at":"2026-05-27T14:16:45Z","cwe_ids":["CWE-78"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-36045"},{"type":"WEB","url":"https://github.com/sipeed/picoclaw/commit/01d694b9985a66c3d7119fc9f74ce8ed4f0f21b5"},{"type":"WEB","url":"https://gist.github.com/NucleiAv/41899be6266a9813840301577792ed68"},{"type":"PACKAGE","url":"https://github.com/sipeed/picoclaw"},{"type":"WEB","url":"https://github.com/sipeed/picoclaw/releases/tag/v0.1.2"}],"affected":[{"package":{"name":"github.com/sipeed/picoclaw","ecosystem":"Go","purl":"pkg:golang/github.com/sipeed/picoclaw"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"0.1.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-cv2p-68f4-f4pw/GHSA-cv2p-68f4-f4pw.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"}]}