


Perceptive Security
SOC/SIEM Consultancy

A security vulnerability has been detected in nanocoai NanoClaw up to 2.0.64. This affects an unknown part of the file container/agent-runner/src/mcp-tools/core…
Published:
5 augustus 2026 om 22:00:00
Alert date:
6 augustus 2026 om 04:01:23
Source:
nvd.nist.gov
Web Technologies, Zero-Day Vulnerabilities
A path traversal vulnerability has been identified in nanocoai NanoClaw versions up to 2.0.64. The flaw exists in the file container/agent-runner/src/mcp-tools/core.ts within the send_file component. An attacker can exploit this vulnerability remotely to traverse directory paths beyond intended boundaries. A public exploit has been disclosed, increasing the risk of active exploitation. The project maintainers were notified via an issue report but have not yet responded or released a patch. The vulnerability is tracked as CVE-2026-18991 and is listed on NVD and VulDB. Users of affected versions should consider mitigating controls until an official fix is available.
Technical details
Mitigation steps:
Affected products:
nanocoai NanoClaw up to 2.0.64
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-18991
https://github.com/nanocoai/nanoclaw/
https://github.com/nanocoai/nanoclaw/issues/2760
https://vuldb.com/cve/CVE-2026-18991
https://vuldb.com/submit/862563
https://vuldb.com/vuln/386367
https://vuldb.com/vuln/386367/cti
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
