CVE-2026-7875 Details
Description
NanoClaw version 1.2.0 and prior contains a host/container filesystem boundary vulnerability in outbound attachment handling and outbox cleanup that allows a compromised or prompt-injected container to read files outside the intended outbox directory by supplying crafted messages_out.id and content.files values or creating symlinked outbox files. Attackers can exploit this vulnerability to trigger host-side reads of arbitrary files and in some cases achieve recursive deletion of paths outside the intended cleanup target.
A vulnerability in NanoClaw allows a compromised or prompt-injected container to read files from the host filesystem and, in some cases, recursively delete files outside of designated directories. This issue arises from improper handling of outbound attachments and outbox cleanup, enabling the exploitation of crafted message IDs and file values, or the creation of symlinked outbox files. The vulnerability affects all versions of NanoClaw.
Users are advised to update to the latest version of NanoClaw, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 7, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/qwibitai/nanoclaw/pull/2001 | CISA-ADP | Issue TrackingPatch |
| https://github.com/qwibitai/nanoclaw/commit/7814e45570edf0024a1a5c2ba9fbc9cb3a49f7f7 | [email protected] | Patch |
| https://github.com/qwibitai/nanoclaw/pull/2001 | [email protected] | Issue TrackingPatch |
| https://github.com/qwibitai/nanoclaw/releases/tag/v1.2.0 | [email protected] | ProductRelease Notes |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| nanoco nanoclaw | <= 1.2.0 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 29, 2026 | Initial Analysis | [email protected] |
| May 7, 2026 | CVE Modified | [email protected] |
| May 7, 2026 | CVE Modified | CISA-ADP |
| May 6, 2026 | New CVE Received | [email protected] |