Intelligence View
⚡ tsecurity.de Intelligence
CVE-2026-18991 | nanocoai NanoClaw up to 2.0.64 send_file core.ts path traversal (Issue 2760)
A vulnerability categorized as critical has been discovered in nanocoai NanoClaw up to 2.0.64. This affects an unknown part of the file container/agent-runner/src/mcp-tools/core.ts of the component send_file. Such manipulation leads to path traversal.
This vulnerability is documented as CVE-2026-18991. The attack can be executed remotely. Additionally, an exploit exists.
The project was informed of the problem early through an issue report but has not responded yet.
SOCIAL SHARE CARD GENERATOR