Sipeed PicoClaw Approval Integrity Vulnerability in Exec Tool Execution

Vulnerability

A time-of-check time-of-use (TOCTOU) vulnerability has been identified in Sipeed PicoClaw versions through 0.2.9. The issue arises in the ExecTool.executeRun function within the file pkg/agent/pipeline_execute.go. This vulnerability allows an attacker to manipulate the 'cwd' argument, creating a race condition that disrupts the approval process for command execution. The exploitation must be performed locally, and the available public exploit could be used to trigger this vulnerability.

Impact

Exploitation of this vulnerability undermines the integrity of the approval process for command execution, allowing approved directory identities to diverge from executed ones. This could lead to unauthorized file accesses or command executions in different directories than intended.

Reproduction

To reproduce this vulnerability, download the integration reproducer and the exploit harness from the provided GitHub Gist links. Place these files in the same directory, and run the control harness to observe the difference in directory identities during the approval and execution phases. The exploit will show how an attacker could manipulate the 'cwd' argument to disrupt the approval process.

Added: Jul 18, 2026, 9:26 AM
Updated: Jul 18, 2026, 9:26 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
4.2
remediation
0.0
relevance
9.8
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.