nanocoai has 5 CVEs on record. 1 was published in the last 90 days. The busiest recent month was June 2026 with 4. The median CVSS is 5.5 (medium). None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.5
- Publish → KEV
- —
- Last 90 days
- 1 prev 4
Worst active — by depth score
CVE-2026-56402Medium· 6.5NanoClaw before 2.1.17 contains a privilege escalation vulnerability in the handleApprovalsResponse function that fails to verify responder role authorization48CVE-2026-90807Medium· 6.3A vulnerability was found in nanocoai NanoClaw up to 2.1.1747CVE-2026-56694Medium· 5.4NanoClaw before 2.1.0 contains a privilege escalation vulnerability in the channel-registration approval flow where handleChannelApprovalResponse fails to validate admin privileges over target agent groups30CVE-2026-56693Medium· 5.5NanoClaw before 2.1.17 contains a privilege escalation vulnerability in the create_agent delivery-action handler that performs privileged central-database writes without host-side authorization checks30CVE-2026-56692Medium· 5.5NanoClaw before 2.1.17 contains a symlink following vulnerability in forwardAttachedFiles that allows container-controlled agents to exfiltrate host-readable files30
nanocoai vulnerabilities
CVEs affecting nanocoai, newest first. Open any entry for full detail, references, and exploit status.
5 CVEsRSS
CVE-2026-90807Medium· 6.3PoCA vulnerability was found in nanocoai NanoClaw up to 2.1.17
A vulnerability was found in nanocoai NanoClaw up to 2.1.17. This issue affects the function forwardAttachedFiles of the file src/modules/agent-to-agent/agent-route.ts of the component Attachment Handler. The manipulation results in link…
CVE-2026-56694Medium· 5.4NanoClaw before 2.1.0 contains a privilege escalation vulnerability in the channel-registration approval flow where handleChannelApprovalResponse fails to validate admin privileges over target agent groups
NanoClaw before 2.1.0 contains a privilege escalation vulnerability in the channel-registration approval flow where handleChannelApprovalResponse fails to validate admin privileges over target agent groups. Scoped admins can submit forge…
CVE-2026-56693Medium· 5.5NanoClaw before 2.1.17 contains a privilege escalation vulnerability in the create_agent delivery-action handler that performs privileged central-database writes without host-side authorization checks
NanoClaw before 2.1.17 contains a privilege escalation vulnerability in the create_agent delivery-action handler that performs privileged central-database writes without host-side authorization checks. Confined agent containers can invok…
CVE-2026-56692Medium· 5.5NanoClaw before 2.1.17 contains a symlink following vulnerability in forwardAttachedFiles that allows container-controlled agents to exfiltrate host-readable files
NanoClaw before 2.1.17 contains a symlink following vulnerability in forwardAttachedFiles that allows container-controlled agents to exfiltrate host-readable files. The host validates attachment filenames using only isSafeAttachmentName …
CVE-2026-56402Medium· 6.5PoCNanoClaw before 2.1.17 contains a privilege escalation vulnerability in the handleApprovalsResponse function that fails to verify responder role authorization
NanoClaw before 2.1.17 contains a privilege escalation vulnerability in the handleApprovalsResponse function that fails to verify responder role authorization. Attackers with a valid questionId can approve or reject privileged actions li…