Executive brief
Sipeed PicoClaw is an AI assistant and automation tool designed for efficient hardware deployment. A security flaw in its initial setup process allows a malicious website to remotely set the administrator password if the user has not yet configured it. This could allow an attacker to take control of the device's dashboard, modify configurations, and manage sensitive credentials.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in the `handleSetup` function within `web/backend/api/auth.go` of Sipeed PicoClaw up to version 0.2.9. The application exposes a public bootstrap endpoint at `POST /api/auth/setup` intended for initial configuration; however, it fails to validate browser provenance headers such as Origin, Referer, or Sec-Fetch-Site. A remote attacker can lure a victim with an uninitialized PicoClaw instance to a malicious webpage, which then silently submits a request to the local launcher to set an attacker-controlled administrator password. This grants the attacker full access to the launcher dashboard, including gateway control and credential management. A patch has been developed (commit 4b02293) to reject cross-site setup requests.
Affected products
- Sipeed PicoClaw <= 0.2.9
Timeline
- 2026-07-18: disclosed: Vulnerability disclosed via GitHub Issue #3072
- 2026-07-18: advisory: NVD and VulDB publish advisory details
- 2026-07-18: patched: Fix merged in commit 4b0229351678f479429b8d8b19207757266f246b
References
- https://github.com/sipeed/picoclaw/
- https://github.com/sipeed/picoclaw/commit/4b0229351678f479429b8d8b19207757266f246b
- https://github.com/sipeed/picoclaw/issues/3072
- https://github.com/sipeed/picoclaw/pull/3160
- https://vuldb.com/cve/CVE-2026-16081
- https://vuldb.com/submit/852943
- https://vuldb.com/vuln/379793