CVE-2026-43992

CRITICAL

JunoClaw: MCP write tools exposed raw BIP-39 mnemonic as a tool-call parameter

Title source: cna
STIX 2.1

Description

JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, every MCP write tool (send_tokens, execute_contract, instantiate_contract, upload_wasm, ibc_transfer, etc.) accepted 'mnemonic: string' as an explicit tool-call parameter. The BIP-39 seed was consequently embedded in the LLM tool-call JSON, exposing it to any transport, log, or telemetry surface in the path between the LLM provider and the MCP process. This vulnerability is fixed in 0.x.y-security-1.

Scores

CVSS v3 9.8
EPSS 0.0022
EPSS Percentile 13.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-200 CWE-312 CWE-522 CWE-532
Status published
Products (1)
Dragonmonk111/junoclaw < v0.x.y-security-1
Published May 12, 2026
Tracked Since May 12, 2026