Impact
The vulnerability resides in the forwardAttachedFiles function of the NanoClaw Attachment Handler, where user-supplied input is used to construct file paths without proper validation. The flaw is a classic Path Traversal issue (CWE‑59) that allows an attacker to craft URLs that cause the application to follow and potentially expose arbitrary files on the server. If successfully exploited, the attacker could read or execute sensitive data, compromising confidentiality and integrity of the system.
Affected Systems
Nanocoai’s NanoClaw component, versions up to and including 2.1.17, is affected. The issue is documented for the file src/modules/agent-to-agent/agent-route.ts within the Attachment Handler. No specific patch version is supplied beyond the commit identifier, but any release derived from 2.1.17 must be assessed.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. An attacker can perform the exploit remotely, as the public exploit has been released. The path traversal flaw is straightforward to exploit given proper input, while the absence of mitigation in the affected version makes the risk tangible for systems still running 2.1.17 or earlier.
OpenCVE Enrichment