Executive brief
Sipeed PicoClaw is an AI assistant framework designed for efficient deployment. A security flaw in its WeCom (Work WeChat) integration allows unauthorized users in a group chat to interact with the AI bot even when it is configured to only respond to direct mentions. This could lead to unauthorized use of AI resources, unintended execution of automated tools, or exposure of sensitive workflows to any member of a group chat.
Technical details
An incorrect authorization vulnerability exists in the `dispatchIncoming` function within `pkg/channels/wecom/wecom.go` of Sipeed PicoClaw. The WeCom inbound channel fails to invoke the `ShouldRespondInGroup` validation helper, which is responsible for enforcing the `mention_only` policy. Consequently, even if `channels.wecom.group_trigger.mention_only` is set to true, the application forwards all group messages to the internal inbound bus. A remote attacker with basic group participant privileges can exploit this to trigger agent execution and downstream tool invocations without the required bot mention. As of the advisory date, no patched version is available.
Affected products
- Sipeed PicoClaw <= 0.2.9
Timeline
- 2026-07-18: disclosed: Vulnerability disclosed via GitHub issue and NVD