CVE-2026-90807
Received Received - Intake

Link Following in NanoClaw up to 2.1.17

Vulnerability report for CVE-2026-90807, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-14

Assigner: VulDB

Description

A vulnerability was found in nanocoai NanoClaw up to 2.1.17. This issue affects the function forwardAttachedFiles of the file src/modules/agent-to-agent/agent-route.ts of the component Attachment Handler. The manipulation results in link following. The attack may be performed from remote. The exploit has been made public and could be used. The patch is identified as 3f9ed607b7e7a4872747295f75286f1c377d7c33. It is advisable to implement a patch to correct this issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-14
Generated
2026-09-14
AI Q&A
2026-09-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
nanocoai nanoclaw to 2.1.17 (inc)
nanocoai nanoclaw to 2.1.17 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-59 The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in NanoClaw up to version 2.1.17, specifically in the attachment handling function. It allows attackers to follow links remotely by manipulating the forwardAttachedFiles function in the agent-route.ts file. A public exploit exists, and a patch is available.

Detection Guidance

The provided CVE data does not include specific detection methods or commands. The vulnerability affects the function forwardAttachedFiles in NanoClaw up to version 2.1.17. Check the version of NanoClaw installed on your system and compare it against 2.1.17 to determine exposure.

Impact Analysis

The vulnerability may allow unauthorized access to linked resources or data through manipulated attachments. Attackers could exploit it to access sensitive information or perform unintended actions if user privileges are involved.

Compliance Impact

This vulnerability allows arbitrary file writes outside the intended session sandbox due to improper link resolution in the attachment forwarding mechanism. This could lead to unauthorized access to sensitive data, data corruption, or further system compromise, which may violate GDPR's data integrity and confidentiality requirements or HIPAA's safeguards for protected health information.

Mitigation Strategies

Apply the patch identified as 3f9ed607b7e7a4872747295f75286f1c377d7c33 to the affected component. If patching is not immediately possible, consider disabling the Attachment Handler component or restricting access to the vulnerable function forwardAttachedFiles.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-90807. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart