Zevorn RT-Claw是中国Zevorn个人开发者开源的一款面向嵌入式设备的智能助手。 Zevorn RT-Claw 0.2.0及之前版本存在授权问题漏洞,该漏洞源于文件claw/services/swarm/swarm.c中的RPC Handler组件的claw_tool_invoke函数处理不当,导致授权问题,远程攻击者可能利用该漏洞进行未授权操作。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-16204 | 6.3 MEDIUM | zevorn rt-claw Telegram-to-AI Tool Execution Flow script.c tool_run_script_execute code in |
| CVE-2026-16201 | 5.3 MEDIUM | zevorn rt-claw http_request net.c claw_net_post information disclosure |
No comments yet