๐Ÿ” CVE Alert

CVE-2026-90807

MEDIUM 6.3

nanocoai NanoClaw Attachment agent-route.ts forwardAttachedFiles link following

CVSS Score
6.3
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability was found in nanocoai NanoClaw up to 2.1.17. This issue affects the function forwardAttachedFiles of the file src/modules/agent-to-agent/agent-route.ts of the component Attachment Handler. The manipulation results in link following. The attack may be performed from remote. The exploit has been made public and could be used. The patch is identified as 3f9ed607b7e7a4872747295f75286f1c377d7c33. It is advisable to implement a patch to correct this issue.

CWE CWE-59
Vendor nanocoai
Product nanoclaw
Published Sep 14, 2026
Stay Ahead of the Next One

Get instant alerts for nanocoai nanoclaw

Be the first to know when new medium vulnerabilities affecting nanocoai nanoclaw are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

nanocoai / NanoClaw
2.1.0 2.1.1 2.1.2 2.1.3 2.1.4 2.1.5 2.1.6 2.1.7 2.1.8 2.1.9 2.1.10 2.1.11 2.1.12 2.1.13 2.1.14 2.1.15 2.1.16 2.1.17

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/403309 vuldb.com: https://vuldb.com/vuln/403309/cti vuldb.com: https://vuldb.com/cve/CVE-2026-90807 vuldb.com: https://vuldb.com/submit/922841 github.com: https://github.com/nanocoai/nanoclaw/issues/2828 github.com: https://github.com/nanocoai/nanoclaw/commit/3f9ed607b7e7a4872747295f75286f1c377d7c33 github.com: https://github.com/nanocoai/nanoclaw/

Credits

๐Ÿ” Eric-a (VulDB User)