nanoclaw vulnerability

NanoClaw before 2.1.17 contains a privilege escalation vulnerability in the create_agent delivery-action handler that performs privileged central-database writes without host-side authorization checks. Confined agent containers can invoke create_agent to create arbitrary agent groups, container configurations, and destinations, escalating beyond their intended confinement boundary.

Published 23 Jun 2026Updated 17 Sep 20263 sources
CVSS 6.8

Source timeline

CVE record published by NVDView source ↗