NanoCo NanoClaw是NanoCo组织的一个轻量级个人AI代理平台。 NanoCo NanoClaw 2.1.17之前版本存在后置链接漏洞,该漏洞源于forwardAttachedFiles中存在符号链接跟随问题,主机仅使用isSafeAttachmentName验证附件文件名,然后通过fs.copyFileSync进行复制,该操作会跟随符号链接而缺乏包含检查,可能导致受容器控制的代理泄露主机可读文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-56402 | 6.5 MEDIUM | NanoClaw < 2.1.17 - Privilege Escalation via Unverified Approval Response Handler |
| CVE-2026-56693 | 5.5 MEDIUM | NanoClaw < 2.1.17 - Privilege Escalation via Unauthorized create_agent System Action |
| CVE-2026-56694 | 5.4 MEDIUM | NanoClaw < 2.1.0 - Privilege Escalation via Forged Channel Approval Callback |
No comments yet