Descripción
A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. This affects the function webhook.ParseRequest of the file pkg/channels/line/line.go of the component LINE Webhook. The manipulation results in authentication bypass by capture-replay. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. The reported GitHub issue was closed automatically with the label -not planned- by a bot.
CVSS 5.3EPSS 0.43%Riesgo 0.55
Ver fuente- Publicación
- 2026-07-18 09:17:07
- Versiones afectadas
- <=0.2.9
- Tipo
- Firmware
- Última modificación
- 2026-07-20 18:16:50
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N