PT-2026-51530 · Nanoclaw · Nanoclaw
CVSS v4.0
6.8
Medium
| Vector | AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
NanoClaw versions prior to 2.1.17
Description
An issue exists in the
forwardAttachedFiles function where the host validates attachment filenames using only isSafeAttachmentName before performing a copy operation with fs.copyFileSync. Because fs.copyFileSync follows symbolic links (symlinks)—which are pointers to other files or directories—without containment checks, container-controlled agents can exfiltrate arbitrary files readable by the host.Recommendations
Update to version 2.1.17 or later.
Exploit
Fix
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nanoclaw