CVE-2026-43989

HIGH

JunoClaw: upload_wasm accepted arbitrary filesystem paths without validation

Title source: cna
STIX 2.1

Description

JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, the upload_wasm MCP tool accepted a filesystem path from the agent and uploaded whatever bytes the path resolved to, with no validation of location, symlink target, file size, or file format. This vulnerability is fixed in 0.x.y-security-1.

Scores

CVSS v3 8.5
EPSS 0.0015
EPSS Percentile 4.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-20 CWE-22 CWE-59 CWE-73
Status published
Products (1)
Dragonmonk111/junoclaw < v0.x.y-security-1
Published May 12, 2026
Tracked Since May 12, 2026