CVE-2026-15317Disclosure

LOWCVSS 2.1 · LOW

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. Affected by this vulnerability is the function WebFetchTool.Execute of the file pkg/tools/integration/web.go of the component Guarded Web Fetch Flow. The manipulation results in server-side request forgery. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. The reported GitHub issue was closed automatically due to inactivity.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-07-10: 307-10
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-15317 A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. Affected by this vulnerability is the function WebFetchTool.Execute of the file pkg/tools/integrat… https://www.cve.org/CVERecord?id=CVE-2026-15317

    Post summary

    A new vulnerability (CVE-2026-15317) in Sipeed PicoClaw up to 0.2.9 was identified, affecting the WebFetchTool.Execute function, with no exploitation, PoC, or patch details disclosed.

    00010828
    57.8K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-15317 A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. Affected by this vulnerability is the function WebFetchTool.Execute of the file pkg/tools/integrat… https://www.cve.org/CVERecord?id=CVE-2026-15317 ----- Traducción: CVE-2026-15317 Se … http://infoflow.cloud`

    Post summary

    CVE‑2026‑15317 has been announced for Sipeed PicoClaw, citing the affected function but lacking technical, exploit, or mitigation details.

    0000041
    91 followersView on X
  • MalwareObserver@MalwareObserver
    General

    🐛 VULNERABILITIES CVE Notify: 🚨 [CVE-2026-15317](https://github.com/sipeed/picoclaw/) A security flaw has been discovered in Sipe... https://github.com/sipeed/picoclaw/ #PatchManagement #Vulnerability #CVE

    Post summary

    A brief alert cites CVE-2026-15317 and links to a GitHub repository, but offers no further detail on vulnerability specifics, exploitation, or remediation.

    0000043
    10 followersView on X

Explore more