CVE-2026-56692

NanoClaw before 2.1.17 contains a symlink following vulnerability in forwardAttachedFiles that allows container-controlled agents to exfiltrate host-readable files. The host validates attachment filenames using only isSafeAttachmentName before copying with fs.copyFileSync, which follows symlinks without containment checks, allowing malicious agents to disclose arbitrary host files.
Configurations

No configuration.

History

23 Jun 2026, 16:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-23 16:17

Updated : 2026-06-24 15:16


NVD link : CVE-2026-56692

Mitre link : CVE-2026-56692

CVE.ORG link : CVE-2026-56692


JSON object : View

Products Affected

No product.

CWE
CWE-59

Improper Link Resolution Before File Access ('Link Following')