PatchSiren

nanocoai CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM nanocoai CVE published 2026-08-06

CVE-2026-18991

AI-assisted PatchSiren debrief based on the supplied source corpus. CVE-2026-18991 is a path traversal vulnerability in nanocoai NanoClaw up to 2.0.64, affecting the send_file component in container/agent-runner/src/mcp-tools/core.ts. Remote exploitation is possible, potentially leading to unauthorized access and data breaches. Users of NanoClaw up to 2.0.64 should review and apply remediation if availabl [truncated]

LOW nanocoai CVE published 2026-07-26

CVE-2026-17434

CVE-2026-17434 is a vulnerability in the handleAddMcpServer function of NanoClaw up to 2.0.64, allowing for improper authorization, which may be exploited remotely. A patch, e5b928783d5c485637565eb07d2967922dfbf8d8, is available to remediate this issue. The vulnerability has a CVSS score of 2.1 and is classified as LOW severity. Users of NanoClaw up to 2.0.64 should apply the patch to prevent improper aut [truncated]

LOW nanocoai CVE published 2026-07-26

CVE-2026-17433

CVE-2026-17433 is a vulnerability in Nanocoai NanoClaw up to 2.0.64, affecting the createChatSdkBridge.setup function in src/channels/chat-sdk-bridge.ts, leading to improper authorization with local attack vectors. The exploit is public, and although the project has been informed, there has been no response. Users should verify affected deployments, review official advisories, and consider compensating co [truncated]

MEDIUM nanocoai CVE published 2026-06-23

CVE-2026-56693

CVE-2026-56693 is a medium-severity privilege escalation vulnerability in NanoClaw before version 2.1.17. The vulnerability allows confined agent containers to invoke the create_agent delivery-action handler, performing privileged central-database writes without host-side authorization checks. This enables the creation of arbitrary agent groups, container configurations, and destinations, effectively esca [truncated]

MEDIUM nanocoai CVE published 2026-06-23

CVE-2026-56692

CVE-2026-56692 is a medium-severity vulnerability in NanoClaw before 2.1.17. The issue is a symlink following vulnerability in the forwardAttachedFiles function, which allows container-controlled agents to exfiltrate host-readable files. The host validates attachment filenames using only the isSafeAttachmentName function before copying with fs.copyFileSync, which follows symlinks without containment check [truncated]

HIGH nanocoai CVE published 2026-06-23

CVE-2026-56402

CVE-2026-56402 is a high-severity privilege escalation vulnerability in NanoClaw before version 2.1.17. The vulnerability is caused by a failure to verify the responder role authorization in the handleApprovalsResponse function. This allows attackers with a valid questionId to approve or reject privileged actions like package installation by submitting approval response payloads without proper role valida [truncated]