Loading market data...
← Back to CVE feed

CVE-2026-16016

HIGH CVSS 7.3 View on NVD ↗

Description

A vulnerability was identified in poco-ai poco-claw up to 0.5.4. This issue affects the function run_task of the file executor/app/api/v1/task.py. The manipulation of the argument callback_url leads to server-side request forgery. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The reported GitHub issue was closed automatically due to inactivity.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Published: Jul 17, 2026 14:17 UTC Modified: Jul 17, 2026 16:17 UTC