CVE-2026-90807 | nanocoai NanoClaw up to 2.1.17 Attachment agent-route.ts forwardAttachedFiles link following (Issue 2828)

SecurityVulns

A vulnerability labeled as critical has been found in nanocoai NanoClaw up to 2.1.17. This issue affects the function forwardAttachedFiles of the file src/modules/agent-to-agent/agent-route.ts of the component Attachment Handler. The manipulation results in link following.

This vulnerability was named CVE-2026-90807. The attack may be performed from remote. In addition, an exploit is available.

It is advisable to implement a patch to correct this issue.VulDB Recent EntriesRead More