CVE-2026-16085

A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. Affected is the function NewContextBuilder of the file pkg/agent/context.go. Such manipulation leads to inclusion of functionality from untrusted control sphere. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. The reported GitHub issue was closed automatically with the label "not planned" by a bot.
Configurations

No configuration.

History

18 Jul 2026, 10:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-18 10:17

Updated : 2026-07-20 19:17


NVD link : CVE-2026-16085

Mitre link : CVE-2026-16085

CVE.ORG link : CVE-2026-16085


JSON object : View

Products Affected

No product.

CWE
CWE-829

Inclusion of Functionality from Untrusted Control Sphere