nanoclaw vulnerability

NanoClaw before 2.1.17 contains a privilege escalation vulnerability in the create_agent delivery-action handler that performs privileged central-database writes without host-side authorization checks. Confined agent containers can invoke create_agent to create arbitrary agent groups, container configurations, and destinations, escalating beyond their intended confinement boundary.

Published 23 Jun 2026Updated 17 Sep 20263 sources
CVSS 6.8

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.