CVE-2026-56692

MEDIUM

NanoClaw < 2.1.17 - Arbitrary File Read via Symlink Following in forwardAttachedFiles

Title source: cna
STIX 2.1

Description

NanoClaw before 2.1.17 contains a symlink following vulnerability in forwardAttachedFiles that allows container-controlled agents to exfiltrate host-readable files. The host validates attachment filenames using only isSafeAttachmentName before copying with fs.copyFileSync, which follows symlinks without containment checks, allowing malicious agents to disclose arbitrary host files.

Scores

CVSS v3 5.5
EPSS 0.0013
EPSS Percentile 3.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-59
Status published
Products (2)
nanocoai/nanoclaw < 2.1.17
nanocoai/nanoclaw 2.1.17
Published Jun 23, 2026
Tracked Since Jun 23, 2026