Junglewise Threat Intelligence

CVE-2026-15668: louisho5 picobot SSRF in WebTool.Execute

CVE-2026-15668 · Severity: medium · CVSS 6.3 · Published 2026-07-14

Technologies: Louisho5 Picobot. Vendors: Louisho5.

Executive brief

louisho5 picobot is a lightweight self-hosted bot. A security flaw in its web tool allows the bot to be manipulated into making unauthorized requests to internal network resources or the local server. This could allow an attacker to bypass network protections to access sensitive internal data or services that are not intended to be public.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in louisho5 picobot versions up to 0.2.0 within the WebTool.Execute function located in internal/agent/tools/web.go. The application fails to properly validate or restrict the 'url' argument, allowing the bot to perform unrestricted fetches against localhost and internal network addresses. A remote attacker with low privileges (sufficient to interact with the bot's tools) can exploit this to probe internal infrastructure or access services bound to the local interface. As of the advisory date, the project maintainers have not responded to the issue report, and no patch is currently available.

Affected products

  • louisho5 picobot up to 0.2.0

Timeline

  • 2026-07-14: advisory: Vulnerability disclosed via VulDB and NVD
  • 2026-07-14: disclosed: Public exploit details disclosed via GitHub issue

References

Related threats