CVE-2026-90807
nanocoai NanoClaw Attachment agent-route.ts forwardAttachedFiles link following
CVSS Score
6.3
EPSS Score
0.0%
EPSS Percentile
0th
A vulnerability was found in nanocoai NanoClaw up to 2.1.17. This issue affects the function forwardAttachedFiles of the file src/modules/agent-to-agent/agent-route.ts of the component Attachment Handler. The manipulation results in link following. The attack may be performed from remote. The exploit has been made public and could be used. The patch is identified as 3f9ed607b7e7a4872747295f75286f1c377d7c33. It is advisable to implement a patch to correct this issue.
| CWE | CWE-59 |
| Vendor | nanocoai |
| Product | nanoclaw |
| Published | Sep 14, 2026 |
Stay Ahead of the Next One
Get instant alerts for nanocoai nanoclaw
Be the first to know when new medium vulnerabilities affecting nanocoai nanoclaw are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
nanocoai / NanoClaw
2.1.0 2.1.1 2.1.2 2.1.3 2.1.4 2.1.5 2.1.6 2.1.7 2.1.8 2.1.9 2.1.10 2.1.11 2.1.12 2.1.13 2.1.14 2.1.15 2.1.16 2.1.17
References
vuldb.com: https://vuldb.com/vuln/403309 vuldb.com: https://vuldb.com/vuln/403309/cti vuldb.com: https://vuldb.com/cve/CVE-2026-90807 vuldb.com: https://vuldb.com/submit/922841 github.com: https://github.com/nanocoai/nanoclaw/issues/2828 github.com: https://github.com/nanocoai/nanoclaw/commit/3f9ed607b7e7a4872747295f75286f1c377d7c33 github.com: https://github.com/nanocoai/nanoclaw/
Credits
๐ Eric-a (VulDB User)