CVE-2026-90807: Link Following in nanocoai NanoClaw
CVE-2026-90807 is a medium severity vulnerability in nanocoai NanoClaw up to version 2.1.17 affecting the Attachment Handler component. The flaw exists in the forwardAttachedFiles function, allowing remote attackers to perform link following. An exploit has been publicly disclosed. A patch identified by commit 3f9ed607b7e7a4872747295f75286f1c377d7c33 is available to remediate this issue.
AI Analysis
Technical Summary
This vulnerability in nanocoai NanoClaw (versions 2.1.0 through 2.1.17) affects the forwardAttachedFiles function in src/modules/agent-to-agent/agent-route.ts within the Attachment Handler component. The issue allows remote attackers to manipulate link following behavior, potentially leading to unintended resource access or redirection. The vulnerability has a CVSS 4.0 base score of 5.3 (medium severity) with network attack vector, low complexity, no privileges required, no user interaction, and low impacts on confidentiality, integrity, and availability. A patch identified by commit 3f9ed607b7e7a4872747295f75286f1c377d7c33 is available to fix the issue.
Potential Impact
The vulnerability enables remote attackers to perform link following through the affected function, which may lead to unintended access or redirection. The impact is rated medium with low confidentiality, integrity, and availability impacts. There is no indication of active exploitation in the wild, but public exploit code exists.
Mitigation Recommendations
A patch identified by commit 3f9ed607b7e7a4872747295f75286f1c377d7c33 is available and should be applied to affected versions (2.1.0 through 2.1.17) to remediate this vulnerability. Implementing this patch is the recommended mitigation.
CVE-2026-90807: Link Following in nanocoai NanoClaw
Description
CVE-2026-90807 is a medium severity vulnerability in nanocoai NanoClaw up to version 2.1.17 affecting the Attachment Handler component. The flaw exists in the forwardAttachedFiles function, allowing remote attackers to perform link following. An exploit has been publicly disclosed. A patch identified by commit 3f9ed607b7e7a4872747295f75286f1c377d7c33 is available to remediate this issue.
CVSS v4.0
Score 5.3medium
Affected software
nanocoai
NanoClaw
pkg:github/nanocoai/nanoclawcpe:2.3:a:nanocoai:nanoclaw:*:*:*:*:*:*:*:*Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in nanocoai NanoClaw (versions 2.1.0 through 2.1.17) affects the forwardAttachedFiles function in src/modules/agent-to-agent/agent-route.ts within the Attachment Handler component. The issue allows remote attackers to manipulate link following behavior, potentially leading to unintended resource access or redirection. The vulnerability has a CVSS 4.0 base score of 5.3 (medium severity) with network attack vector, low complexity, no privileges required, no user interaction, and low impacts on confidentiality, integrity, and availability. A patch identified by commit 3f9ed607b7e7a4872747295f75286f1c377d7c33 is available to fix the issue.
Potential Impact
The vulnerability enables remote attackers to perform link following through the affected function, which may lead to unintended access or redirection. The impact is rated medium with low confidentiality, integrity, and availability impacts. There is no indication of active exploitation in the wild, but public exploit code exists.
Mitigation Recommendations
A patch identified by commit 3f9ed607b7e7a4872747295f75286f1c377d7c33 is available and should be applied to affected versions (2.1.0 through 2.1.17) to remediate this vulnerability. Implementing this patch is the recommended mitigation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulDB
- Date Reserved
- 2026-09-13T16:00:34.907Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6aa8711655bf5e2cf5b3ea98
Added to database: 09/14/2026, 22:11:34 UTC
Last enriched: 09/14/2026, 22:13:26 UTC
Last updated: 09/15/2026, 03:22:23 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.