What is CVE-2026-18991?
CVE-2026-18991 is a path traversal vulnerability in the `send_file` component of nanocoai NanoClaw up to version 2.0.64. It allows remote attackers to gain unauthorized file access through manipulation of the `core.ts` file. Users should immediately apply the security patch and enforce proper input validation.
Azərbaycanca: CVE-2026-18991 nanocoai NanoClaw 2.0.64-ə qədər olan versiyalarda `send_file` komponentində yol keçidi (path traversal) zəifliyidir. Bu, uzaqdan hücumçuya `core.ts` faylı vasitəsilə sistemdəki fayllara icazəsiz giriş imkanı yaradır. İstifadəçilər dərhal təhlükəsizlik yeniləməsini tətbiq etməli və müvafiq giriş yoxlamalarını aktivləşdirməlidir.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
In which product and component was CVE-2026-18991 discovered?
This vulnerability was discovered in the `send_file` component of nanocoai NanoClaw up to version 2.0.64.
What capability does an attacker gain by exploiting CVE-2026-18991?
A remote attacker can gain unauthorized access to files on the system through manipulation of the `core.ts` file.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.