Sipeed PicoClaw
- <= 0.2.9
An authorization bypass vulnerability has been identified in Sipeed PicoClaw versions through 0.2.9, specifically within the WeCom group message handling component. The issue arises in the 'dispatchIncoming' function of 'wecom.go', where the application fails to properly enforce group trigger policies. This flaw allows unmentioned group messages to be processed by the PicoClaw agent, contradicting the intended 'mention-only' requirement. The vulnerability can be exploited remotely, and the published exploit may be used for attacks.
Exploitation of this vulnerability bypasses authorization checks, allowing unauthorized prompt injection into the PicoClaw agent. This could lead to unintended tool activations or actions within the agent, causing unnecessary resource consumption and potentially disrupting expected workflows.
To reproduce this vulnerability, deploy PicoClaw with the WeCom channel configured to require mentions for group messages. Then, send an unmentioned message in a group chat where the bot is a participant. The message will be processed by the PicoClaw agent, demonstrating the bypass.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.