CVE-2026-18991: nanocoai NanoClaw send_file core.ts path traversal
A security vulnerability has been detected in nanocoai NanoClaw up to 2.0.64. This affects an unknown part of the file container/agent-runner/src/mcp-tools/core.ts of the component sendfile. Such manipulation leads to path traversal. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18991?
CVE-2026-18991 has a severity rating of 7.3, classified as high.
How do I fix CVE-2026-18991?
Fixes for CVE-2026-18991 should include updating nanocoai NanoClaw to the latest version that addresses the path traversal vulnerability.
What type of vulnerability is CVE-2026-18991?
CVE-2026-18991 is classified as a path traversal vulnerability.
Where does CVE-2026-18991 affect the software?
CVE-2026-18991 affects the send_file function in the core.ts file of the nanocoai NanoClaw software.
Can CVE-2026-18991 be exploited remotely?
Yes, CVE-2026-18991 can be executed as a remote attack.