PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-18991 nanocoai CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. CVE-2026-18991 is a path traversal vulnerability in nanocoai NanoClaw up to 2.0.64, affecting the send_file component in container/agent-runner/src/mcp-tools/core.ts. Remote exploitation is possible, potentially leading to unauthorized access and data breaches. Users of NanoClaw up to 2.0.64 should review and apply remediation if available. The project was informed early but has not responded yet. Evidence from Vuldb and NVD suggests a path traversal vulnerability exists. Defenders should verify affected product deployments, review official advisories, and track exceptions.

Vendor
nanocoai
Product
NanoClaw
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-06
Original CVE updated
2026-08-06
Advisory published
2026-08-06
Advisory updated
2026-08-06

Who should care

Users of nanocoai NanoClaw up to 2.0.64, particularly those with exposure to the send_file component, should review and apply remediation if available. Affected operators, platforms, and security teams should prioritize vulnerability management and implement compensating controls for exposed systems.

Technical summary

CVE-2026-18991 is a path traversal vulnerability in nanocoai NanoClaw up to 2.0.64. The vulnerability affects an unknown part of the file container/agent-runner/src/mcp-tools/core.ts in the send_file component. Remote exploitation is possible. Affected product context suggests users of NanoClaw up to 2.0.64 should review and apply remediation if available. Defensive impact includes potential unauthorized access and data breaches.

Defensive priority

Medium-priority defensive review recommended due to potential remote exploitation of path traversal vulnerability.

Recommended defensive actions

  • Review and apply vendor remediation if available
  • Inventory checks for affected NanoClaw versions
  • Implement compensating controls and monitoring
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

Evidence from Vuldb and NVD suggests a path traversal vulnerability exists in nanocoai NanoClaw up to 2.0.64. The vulnerability affects an unknown part of the file container/agent-runner/src/mcp-tools/core.ts in the send_file component. Detailed impact and affected scope are unclear. Defenders should verify affected product deployments, review official advisories, and track exceptions. Evidence limits suggest remote exploitation is possible but require further review.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T03:16:22.130Z and has not been modified since then.