Executive brief
Sipeed PicoClaw, an AI assistant framework, contains a security flaw in how it handles messages from the Feishu platform. The system is designed to only process messages from authorized users; however, an unauthorized user can bypass these restrictions by having an authorized user reply to one of their previous messages. This allows untrusted content to be fed into the AI model, potentially leading to unauthorized actions or the manipulation of the AI's behavior.
Technical details
A missing authorization check exists in the Feishu channel's message handling logic within `pkg/channels/feishu/feishu_64.go`. While the `handleMessageReceive` function validates the current sender against the `allow_from` list, the `prependReplyContext` function fetches and imports the body of parent/replied messages without re-verifying the original author's authorization status. A remote attacker who is not on the allowlist can exploit this by having an authorized user reply to their message, causing the untrusted content to be injected into the downstream AI agent's context. This can be used for prompt injection or to influence automated decisions. As of the advisory date, no official patch has been confirmed.
Affected products
- Sipeed PicoClaw <= 0.2.9
Timeline
- 2026-07-18: disclosed: Vulnerability disclosed via GitHub issue and NVD