CRITICALCVE-2026-7875Published Modified CNA VulnCheck
CVE-2026-7875: NanoClaw Host/Container Filesystem Boundary Vulnerability via Outbound Attachment Handling
NanoClaw version 1.2.0 and prior contains a host/container filesystem boundary vulnerability in outbound attachment handling and outbox cleanup that allows a compromised or prompt-injected container to read files outside the intended outbox directory by supplying crafted messages_out.id and content.files values or creating symlinked outbox files. Attackers can exploit this vulnerability to trigger host-side reads of arbitrary files and in some cases achieve recursive deletion of paths outside the intended cleanup target.
Metrics
- CVSS v4.0
- 9.3
- Severity
- CRITICAL
- Fixed in
- 7814e45570edf0024a1a5c2ba9fbc9cb3a49f7f7
- Affected Products
- 1
Affected packages
- Qwibit / NanoClaw≤ 1.2.0Fixed in 7814e45570edf0024a1a5c2ba9fbc9cb3a49f7f7
CVSS Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:HReferences