Sipeed PicoClaw Missing Authorization Vulnerability in WebSocket Channel

Vulnerability

A vulnerability exists in Sipeed PicoClaw versions up to 0.2.9, specifically within the WebSocket channel handling. The issue arises in the 'rt.ReloadConfig' function, where the 'message.send' argument can be manipulated to bypass authorization. This flaw allows authenticated Pico WebSocket clients to trigger an unauthorized configuration reload action, exploiting a control-plane mutation path. The vulnerability can be exploited remotely, and the details of the exploit are publicly available.

Impact

Exploitation of this vulnerability creates an authorization bypass on a control-plane mutation action. Authenticated Pico clients can invoke a live gateway configuration reload from a standard chat message, disrupting service stability and interfering with administrative changes. This unauthorized operational capability can repeatedly restart channel and runtime states, risking the integrity and availability of the running gateway control plane.

Reproduction

To reproduce this vulnerability, first ensure that PicoClaw is running a version prior to 0.2.9 with the Pico channel enabled. Connect as an authenticated WebSocket client and send a 'message.send' payload containing the command '/reload'. The absence of any authorization checks will allow the command to be executed, triggering a live configuration reload on the gateway.

Added: Jul 10, 2026, 3:22 AM
Updated: Jul 10, 2026, 3:22 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
8.0
remediation
0.0
relevance
9.3
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.