Sipeed PicoClaw
- <= 0.2.9
A server-side request forgery (SSRF) vulnerability has been identified in Sipeed PicoClaw versions through 0.2.9. The issue arises in the web_fetch function within the file pkg/tools/integration/web.go. This vulnerability allows remote exploitation by bypassing the application's IP validation checks, particularly for ISATAP IPv6 addresses that embed private IPv4 loops. As a result, crafted URLs can be used to access internal services that should be protected.
Exploitation of this vulnerability bypasses the application's built-in safeguards against accessing private or local network resources via the web_fetch tool. This could lead to unauthorized access of internal services, such as admin interfaces or metadata endpoints, depending on the application's deployment context.
The vulnerability can be reproduced by sending a request through the web_fetch tool with an ISATAP IPv6 address that embeds a private IPv4 address, such as 127.0.0.1. The request will bypass the private host checks and be allowed through, demonstrating the vulnerability.
Users are advised to update to Sipeed PicoClaw version 0.3.1 or later, where this vulnerability has been patched.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.