Sipeed PicoClaw WeCom Group Message Handler Authorization Bypass Vulnerability

Vulnerability

An authorization bypass vulnerability has been identified in Sipeed PicoClaw versions through 0.2.9, specifically within the WeCom group message handling component. The issue arises in the 'dispatchIncoming' function of 'wecom.go', where the application fails to properly enforce group trigger policies. This flaw allows unmentioned group messages to be processed by the PicoClaw agent, contradicting the intended 'mention-only' requirement. The vulnerability can be exploited remotely, and the published exploit may be used for attacks.

Impact

Exploitation of this vulnerability bypasses authorization checks, allowing unauthorized prompt injection into the PicoClaw agent. This could lead to unintended tool activations or actions within the agent, causing unnecessary resource consumption and potentially disrupting expected workflows.

Reproduction

To reproduce this vulnerability, deploy PicoClaw with the WeCom channel configured to require mentions for group messages. Then, send an unmentioned message in a group chat where the bot is a participant. The message will be processed by the PicoClaw agent, demonstrating the bypass.

Added: Jul 18, 2026, 11:24 PM
Updated: Jul 18, 2026, 11:24 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
8.0
remediation
0.0
relevance
9.7
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.