---
id: CVE-2026-16082
title: A vulnerability was identified in Sipeed PicoClaw up to 0.2.9
summary: >-
  A vulnerability was identified in Sipeed PicoClaw up to 0.2.9. The impacted
  element is the function ExecTool.executeRun of the file
  pkg/agent/pipeline_execute.go. The manipulation of the argument cwe leads to
  time-of-check time-of-use. T…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-362
  - CWE-367
published: '2026-07-18'
updated: '2026-07-18'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-16082'
references:
  - url: 'https://github.com/sipeed/picoclaw/'
    label: cna@vuldb.com
  - url: 'https://github.com/sipeed/picoclaw/issues/3081'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-16082'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/852944'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/379794'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/379794/cti'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.00124
epssPercentile: 0.0247
ingestedAt: '2026-07-19T02:27:12.430Z'
---

## Overview

A vulnerability was identified in Sipeed PicoClaw up to 0.2.9. The impacted element is the function ExecTool.executeRun of the file pkg/agent/pipeline_execute.go. The manipulation of the argument cwe leads to time-of-check time-of-use. The attack must be carried out locally. The exploit is publicly available and might be used. The reported GitHub issue was closed automatically with the label "not planned" by a bot.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
