Executive brief
JunoClaw is an AI platform that allows automated agents to interact with the Juno blockchain network. A security flaw in the platform's bridge component allows malicious or compromised AI agents to force the server to make unauthorized network requests. This could lead to the theft of sensitive cloud credentials, access to private internal services, or the exposure of internal network data, potentially compromising the entire hosting environment.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in the JunoClaw WAVS bridge's `computeDataVerify` function within `local-compute.ts`. The component uses the `fetch()` API on URLs provided by AI agents without validating the protocol scheme, port, or destination IP address. An attacker can exploit this to perform unauthorized requests to internal services, loopback interfaces, or cloud metadata services (e.g., 169.254.169.254) to exfiltrate IAM tokens or sensitive configuration data. The vulnerability is mitigated in version v0.x.y-security-1 by implementing a new `ssrf-guard` module that enforces scheme/port allowlists and performs DNS pre-resolution to block private and reserved IP ranges.
Affected products
- Dragonmonk111 JunoClaw WAVS bridge (junoclaw/wavs-bridge) < v0.x.y-security-1
Timeline
- 2026-04-26: patched: Fix released in version v0.x.y-security-1
- 2026-05-12: disclosed: CVE-2026-43993 published