Executive brief
Sipeed PicoClaw, an AI assistant framework, contains a security flaw in how it handles MQTT messages. The system incorrectly trusts a user-provided ID within the message topic to verify who sent the message, rather than using secure authentication from the message broker. This allows an attacker to bypass access controls and send unauthorized commands to the AI assistant by pretending to be a permitted user.
Technical details
An improper authorization vulnerability (CWE-285/CWE-863) exists in Sipeed PicoClaw up to version 0.2.9 within the MQTT channel implementation (`pkg/channels/mqtt/mqtt.go`). The application extracts the `client_id` directly from the MQTT request topic string (`/picoclaw/{agent_id}/{client_id}/request`) and uses it as the primary security principal for authorization checks. Because this value is client-controlled and not verified against broker-authenticated metadata, a remote attacker with the ability to publish to the MQTT broker can impersonate any allowlisted user. This allows unauthorized ingress to the inbound message bus. A public exploit is available, and the issue was identified in GitHub issue #3068.
Affected products
- Sipeed PicoClaw up to 0.2.9
Timeline
- 2026-07-10: advisory: NVD publication date
- 2026-07-10: disclosed: Public disclosure via GitHub and VulDB