CVE-2026-16083
MEDIUMSipeed PicoClaw LINE Webhook line.go webhook.ParseRequest authentication replay
Title source: cnaDescription
A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. This affects the function webhook.ParseRequest of the file pkg/channels/line/line.go of the component LINE Webhook. The manipulation results in authentication bypass by capture-replay. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. The reported GitHub issue was closed automatically with the label "not planned" by a bot.
References (6)
Core 6
Core References
Vdb Entry, Technical Description vdb-entry
technical-description
VDB-379795 | Sipeed PicoClaw LINE Webhook line.go webhook.ParseRequest authentication replay
https://vuldb.com/vuln/379795
Signature, Permissions Required signature
permissions-required
VDB-379795 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/379795/cti
Third Party Advisory third-party-advisory
CVE-2026-16083 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-16083
Third Party Advisory third-party-advisory
Submit #852945 | Sipeed PicoClaw <= 0.2.9 Authentication Bypass by Capture-replay (CWE-294)
https://vuldb.com/submit/852945
Exploit exploit
issue-tracking
https://github.com/sipeed/picoclaw/issues/3073
Product product
https://github.com/sipeed/picoclaw/
Scores
CVSS v3
5.3
EPSS
0.0043
EPSS Percentile
35.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-287
CWE-294
Status
published
Products (10)
Sipeed/PicoClaw
0.2.0
Sipeed/PicoClaw
0.2.1
Sipeed/PicoClaw
0.2.2
Sipeed/PicoClaw
0.2.3
Sipeed/PicoClaw
0.2.4
Sipeed/PicoClaw
0.2.5
Sipeed/PicoClaw
0.2.6
Sipeed/PicoClaw
0.2.7
Sipeed/PicoClaw
0.2.8
Sipeed/PicoClaw
0.2.9
Published
Jul 18, 2026
Tracked Since
Jul 18, 2026