Louis Picobot是中国Louis个人开发者的一款自动化流程调度软件。 Louis Picobot 0.2.0及之前版本存在服务端请求伪造漏洞,该漏洞源于web Tool组件中internal/agent/tools/web.go文件的WebTool.Execute函数对参数url操作不当,导致服务端请求伪造。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-15629 | 6.3 MEDIUM | louisho5 picobot Workspace filesystem.go GetSkill link following |
| CVE-2026-15669 | 5.3 MEDIUM | louisho5 picobot exec Tool exec.go ExecTool.Execute os command injection |
No comments yet