Description
A vulnerability was found in nanocoai NanoClaw up to 2.1.17. This issue affects the function forwardAttachedFiles of the file src/modules/agent-to-agent/agent-route.ts of the component Attachment Handler. The manipulation results in link following. The attack may be performed from remote. The exploit has been made public and could be used. The patch is identified as 3f9ed607b7e7a4872747295f75286f1c377d7c33. It is advisable to implement a patch to correct this issue.
Published: 2026-09-14
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote link following that may expose protected files
Action: Patch Now
AI Analysis

Impact

The vulnerability resides in the forwardAttachedFiles function of the NanoClaw Attachment Handler, where user-supplied input is used to construct file paths without proper validation. The flaw is a classic Path Traversal issue (CWE‑59) that allows an attacker to craft URLs that cause the application to follow and potentially expose arbitrary files on the server. If successfully exploited, the attacker could read or execute sensitive data, compromising confidentiality and integrity of the system.

Affected Systems

Nanocoai’s NanoClaw component, versions up to and including 2.1.17, is affected. The issue is documented for the file src/modules/agent-to-agent/agent-route.ts within the Attachment Handler. No specific patch version is supplied beyond the commit identifier, but any release derived from 2.1.17 must be assessed.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. An attacker can perform the exploit remotely, as the public exploit has been released. The path traversal flaw is straightforward to exploit given proper input, while the absence of mitigation in the affected version makes the risk tangible for systems still running 2.1.17 or earlier.

Generated by OpenCVE AI on September 15, 2026 at 07:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update NanoClaw to the patched version identified by commit 3f9ed607b7e7a4872747295f75286f1c377d7c33, which hardens the forwardAttachedFiles function against URL manipulation.
  • If updating is delayed, disable or restrict the Attachment Handler’s forwardAttachedFiles endpoint to prevent external link following until the patch can be applied.
  • Monitor application logs for anomalous access patterns indicating path traversal attempts and apply network level filtering to block unexpected URL references.

Generated by OpenCVE AI on September 15, 2026 at 07:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in nanocoai NanoClaw up to 2.1.17. This issue affects the function forwardAttachedFiles of the file src/modules/agent-to-agent/agent-route.ts of the component Attachment Handler. The manipulation results in link following. The attack may be performed from remote. The exploit has been made public and could be used. The patch is identified as 3f9ed607b7e7a4872747295f75286f1c377d7c33. It is advisable to implement a patch to correct this issue.
Title nanocoai NanoClaw Attachment agent-route.ts forwardAttachedFiles link following
First Time appeared Nanocoai
Nanocoai nanoclaw
Weaknesses CWE-59
CPEs cpe:2.3:a:nanocoai:nanoclaw:*:*:*:*:*:*:*:*
Vendors & Products Nanocoai
Nanocoai nanoclaw
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Nanocoai Nanoclaw
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-16T15:59:52.020Z

Reserved: 2026-09-13T16:00:34.907Z

Link: CVE-2026-90807

cve-icon Vulnrichment

Updated: 2026-09-16T15:59:47.067Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T18:20:28.530

Modified: 2026-09-16T17:18:17.493

Link: CVE-2026-90807

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T08:00:16Z

Weaknesses
  • CWE-59

    Improper Link Resolution Before File Access ('Link Following')