CVE-2026-15622 Details
Description
A flaw has been found in poco-ai poco-claw up to 0.5.4. Affected is the function get_workspace_file of the file executor_manager/app/api/v1/workspace.py of the component Workspace API. Executing a manipulation of the argument user_id can lead to authorization bypass. The attack may be launched remotely. The exploit has been published and may be used. This patch is called 67fcc88505c57f77d3fcf04eb5b89425b10cbf48. Upgrading the affected component is recommended.
An authorization bypass vulnerability has been identified in the Poco-AI Poco-Claw application, specifically in versions up to 0.5.4. The issue resides in the Workspace API, within the 'get_workspace_file' function of 'executor_manager/app/api/v1/workspace.py'. The vulnerability allows unauthorized access to workspace files by manipulating the 'user_id' parameter in the request. This flaw can be exploited remotely, potentially leading to unauthorized disclosure of sensitive information such as source code, task artifacts, and embedded credentials.
Users are advised to upgrade to version 0.5.5 or later, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 14, 2026CISA-ADP
Assessed Jul 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/poco-ai/poco-claw/ | [email protected] | ProductSource CodeVendor |
| https://github.com/poco-ai/poco-claw/commit/67fcc88505c57f77d3fcf04eb5b89425b10cbf48 | [email protected] | Source CodeVendor |
| https://github.com/poco-ai/poco-claw/issues/133 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/poco-ai/poco-claw/pull/135 | [email protected] | Issue TrackingVendor |
| https://vuldb.com/cve/CVE-2026-15622 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/855797 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/378125 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/378125/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-285 | Improper Authorization | [email protected] |
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| poco-ai poco-claw | <= 0.5.4 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 14, 2026 | CVE Modified | CISA-ADP |
| Jul 14, 2026 | New CVE Received | [email protected] |
Volerion