PT-2026-51531 · Nanoclaw · Nanoclaw
CVSS v4.0
6.8
Medium
| Vector | AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
NanoClaw versions prior to 2.1.17
Description
A privilege escalation issue exists in the
create agent delivery-action handler. The handler performs privileged central-database writes without implementing host-side authorization checks. This allows confined agent containers to invoke create agent to create arbitrary agent groups, container configurations, and destinations, enabling them to escalate privileges beyond their intended confinement boundary.Recommendations
Update to version 2.1.17 or later.
Exploit
Fix
LPE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nanoclaw