Executive brief
Picobot is a lightweight self-hosted automation bot. A security flaw in its command execution tool allows a local user or a malicious model-driven request to bypass safety restrictions and run unauthorized system commands. This could lead to the theft of sensitive data, exposure of credentials, or full control over the host system where the bot is running.
Technical details
An OS command injection vulnerability exists in the `ExecTool.Execute` function within `internal/agent/tools/exec.go`. The component attempts to restrict command execution using a blacklist of dangerous programs and basic path validation; however, it only validates the first element of an input array. An attacker can bypass these checks by using shell wrappers like `sh -c` or `bash -lc` to execute arbitrary payloads. This allows for arbitrary command execution under the context of the Picobot process. The vulnerability is reachable via the default agent loop and has been demonstrated using a local OpenAI-compatible stub provider. As of the advisory date, no patch has been released by the maintainer.
Affected products
- louisho5 picobot <= 0.2.0
Timeline
- 2026-06-10: disclosed: Issue reported to the maintainer via GitHub issue #42
- 2026-07-14: advisory: CVE published by VulDB/NVD