← Späť na vyhľadávanie CVE

CVE-2026-56692

NanoClaw

Popis

NanoClaw before 2.1.17 contains a symlink following vulnerability in forwardAttachedFiles that allows container-controlled agents to exfiltrate host-readable files. The host validates attachment filenames using only isSafeAttachmentName before copying with fs.copyFileSync, which follows symlinks without containment checks, allowing malicious agents to disclose arbitrary host files.

CVSS 5.5EPSS 0.131%Riziko 0.56
Zobraziť zdroj
Zverejnené
2026-06-23 16:17:05
Dotknuté verzie
<2.1.17
Typ
Kritický softvér
Vektor
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N