CVE-2026-15669

Severity CVSS v4.0:
LOW
Type:
CWE-77 Command Injection
Publication date:
14/07/2026
Last modified:
14/07/2026

Description

A vulnerability was found in louisho5 picobot up to 0.2.0. This issue affects the function ExecTool.Execute of the file internal/agent/tools/exec.go of the component exec Tool. The manipulation results in os command injection. The attack requires a local approach. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.