CVE-2026-6987 | PicoClaw up to 0.2.4 Web Launcher Management Plane /api/gateway/restart command injection (Issue 2307 / EUVD-2026-25663)
A vulnerability identified as critical has been detected in PicoClaw up to 0.2.4. Impacted is an unknown function of the file /api/gateway/restart of the component Web Launcher Management Plane. Performing a manipulation results in command injection.
This vulnerability is cataloged as CVE-2026-6987. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
The project was informed of the problem early through an issue report but has not responded yet.