HarborGuard / CVE
Back to search
CRITICALCVE-2026-7875Published Modified CNA VulnCheck

CVE-2026-7875: NanoClaw Host/Container Filesystem Boundary Vulnerability via Outbound Attachment Handling

NanoClaw version 1.2.0 and prior contains a host/container filesystem boundary vulnerability in outbound attachment handling and outbox cleanup that allows a compromised or prompt-injected container to read files outside the intended outbox directory by supplying crafted messages_out.id and content.files values or creating symlinked outbox files. Attackers can exploit this vulnerability to trigger host-side reads of arbitrary files and in some cases achieve recursive deletion of paths outside the intended cleanup target.

Metrics

CVSS v4.0
9.3
Severity
CRITICAL
Fixed in
7814e45570edf0024a1a5c2ba9fbc9cb3a49f7f7
Affected Products
1

Fix available

7814e45570edf0024a1a5c2ba9fbc9cb3a49f7f7
Patch commits
Affected packages
  • Qwibit / NanoClaw
    ≤ 1.2.0
    Fixed in 7814e45570edf0024a1a5c2ba9fbc9cb3a49f7f7
CVSS Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H