CVE-2026-56692

Severity CVSS v4.0:
MEDIUM
Type:
CWE-59 Link Following
Publication date:
23/06/2026
Last modified:
24/06/2026

Description

NanoClaw before 2.1.17 contains a symlink following vulnerability in forwardAttachedFiles that allows container-controlled agents to exfiltrate host-readable files. The host validates attachment filenames using only isSafeAttachmentName before copying with fs.copyFileSync, which follows symlinks without containment checks, allowing malicious agents to disclose arbitrary host files.