A vulnerability has been found in louisho5 picobot up to 0.2.0. This vulnerability affects the function WebTool.Execute of the file internal/agent/tools/web.go of the component web Tool. The manipulation of the argument url leads to server-side request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
References
Configurations
No configuration.
History
15 Jul 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://vuldb.com/submit/855866 - |
14 Jul 2026, 05:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-14 05:16
Updated : 2026-07-15 15:16
NVD link : CVE-2026-15668
Mitre link : CVE-2026-15668
CVE.ORG link : CVE-2026-15668
JSON object : View
Products Affected
No product.
CWE
CWE-918
Server-Side Request Forgery (SSRF)
