Sipeed PicoClaw MQTT Channel Authorization Bypass Vulnerability

Vulnerability

An authorization bypass vulnerability has been identified in Sipeed PicoClaw versions through 0.2.9, specifically within the MQTT channel handler. The issue arises because the authorization process relies on the client-defined 'client_id' segment of the MQTT topic, which can be easily spoofed. This manipulation allows unauthorized messages to be sent to the agent, bypassing the intended safeguards. The vulnerability can be exploited remotely, and a public exploit is available.

Impact

Exploitation of this vulnerability allows for unauthorized messages to be sent to the PicoClaw agent, bypassing the MQTT channel's authorization controls. This could lead to unauthorized prompts being processed by the agent, potentially triggering downstream actions or tool executions, and consuming model or API resources.

Reproduction

To reproduce this vulnerability, first ensure that Sipeed PicoClaw version 0.2.9 or earlier is running with the MQTT channel enabled. Configure the 'allow_from' setting to include a specific client ID, such as 'allowed-user'. Once the MQTT channel is active, publish a message to the request topic using a spoofed client ID. The message will be accepted by the agent, demonstrating the bypassed authorization.

Remediation

Users can update to Sipeed PicoClaw version 0.2.10 or later, where this vulnerability has been patched.

Added: Jul 10, 2026, 2:22 AM
Updated: Jul 10, 2026, 2:22 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
8.7
remediation
0.0
relevance
9.3
threat
6.4
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.