๐Ÿ” CVE Alert

CVE-2026-56692

MEDIUM 5.5

NanoClaw < 2.1.17 - Arbitrary File Read via Symlink Following in forwardAttachedFiles

CVSS Score
5.5
EPSS Score
0.0%
EPSS Percentile
0th

NanoClaw before 2.1.17 contains a symlink following vulnerability in forwardAttachedFiles that allows container-controlled agents to exfiltrate host-readable files. The host validates attachment filenames using only isSafeAttachmentName before copying with fs.copyFileSync, which follows symlinks without containment checks, allowing malicious agents to disclose arbitrary host files.

CWE CWE-59
Vendor nanocoai
Product nanoclaw
Published Jun 23, 2026
Stay Ahead of the Next One

Get instant alerts for nanocoai nanoclaw

Be the first to know when new medium vulnerabilities affecting nanocoai nanoclaw are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

nanocoai / nanoclaw
0 < 2.1.17

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/nanocoai/nanoclaw/pull/2468 github.com: https://github.com/nanocoai/nanoclaw/commit/28032bc0eca76c91fb3d8be0013e8bcaf2f5aeae vulncheck.com: https://www.vulncheck.com/advisories/nanoclaw-arbitrary-file-read-via-symlink-following-in-forwardattachedfiles

Credits

Chia Min Jun Lennon