VulnSea

nanocoai has 5 CVEs on record. 1 was published in the last 90 days. The busiest recent month was June 2026 with 4. The median CVSS is 5.5 (medium). None have a confirmed exploitation report.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
5.5
Publish → KEV
Last 90 days
1 prev 4

Products

  • NanoClaw 5
5
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

nanocoai vulnerabilities

CVEs affecting nanocoai, newest first. Open any entry for full detail, references, and exploit status.

5 CVEsRSS

CVE-2026-90807Medium· 6.3PoC
1w ago

A vulnerability was found in nanocoai NanoClaw up to 2.1.17

A vulnerability was found in nanocoai NanoClaw up to 2.1.17. This issue affects the function forwardAttachedFiles of the file src/modules/agent-to-agent/agent-route.ts of the component Attachment Handler. The manipulation results in link…

Twilightnanocoai · NanoClawEPSS 0.29%via NVD
CVE-2026-56694Medium· 5.4
3mo ago

NanoClaw before 2.1.0 contains a privilege escalation vulnerability in the channel-registration approval flow where handleChannelApprovalResponse fails to validate admin privileges over target agent groups

NanoClaw before 2.1.0 contains a privilege escalation vulnerability in the channel-registration approval flow where handleChannelApprovalResponse fails to validate admin privileges over target agent groups. Scoped admins can submit forge…

Sunlitnanocoai · nanoclawEPSS 0.29%via NVD
CVE-2026-56693Medium· 5.5
3mo ago

NanoClaw before 2.1.17 contains a privilege escalation vulnerability in the create_agent delivery-action handler that performs privileged central-database writes without host-side authorization checks

NanoClaw before 2.1.17 contains a privilege escalation vulnerability in the create_agent delivery-action handler that performs privileged central-database writes without host-side authorization checks. Confined agent containers can invok…

Sunlitnanocoai · nanoclawEPSS 0.17%via NVD
CVE-2026-56692Medium· 5.5
3mo ago

NanoClaw before 2.1.17 contains a symlink following vulnerability in forwardAttachedFiles that allows container-controlled agents to exfiltrate host-readable files

NanoClaw before 2.1.17 contains a symlink following vulnerability in forwardAttachedFiles that allows container-controlled agents to exfiltrate host-readable files. The host validates attachment filenames using only isSafeAttachmentName …

Sunlitnanocoai · nanoclawEPSS 0.17%via NVD
CVE-2026-56402Medium· 6.5PoC
3mo ago

NanoClaw before 2.1.17 contains a privilege escalation vulnerability in the handleApprovalsResponse function that fails to verify responder role authorization

NanoClaw before 2.1.17 contains a privilege escalation vulnerability in the handleApprovalsResponse function that fails to verify responder role authorization. Attackers with a valid questionId can approve or reject privileged actions li…

Twilightnanocoai · nanoclawEPSS 0.38%via NVD
nanocoai vulnerabilities (CVEs) · VulnSea