Executive brief
NanoClaw, a platform for managing autonomous agent containers, contains a security flaw that allows restricted agents to bypass their isolation. By exploiting this vulnerability, a confined agent can create unauthorized new agent groups and configurations, potentially gaining higher-level access to the system's central database. This could allow an attacker to escalate their privileges and interfere with the management of other agents or system resources.
Technical details
A privilege escalation vulnerability exists in NanoClaw's 'create_agent' delivery-action handler due to improper client-side enforcement of server-side security (CWE-602). The root cause is a lack of host-side authorization checks; the system previously relied on the untrusted agent container to gate access to the 'create_agent' tool. An attacker with low-privileged access within a confined agent container can manually invoke the 'create_agent' action to perform unauthorized writes to the central database, including 'agent_groups', 'container_configs', and 'agent_destinations'. This allows the attacker to escalate beyond their intended confinement boundary. The issue is resolved in version 2.1.17 by implementing host-side CLI scope verification.
Affected products
- nanocoai nanoclaw < 2.1.17
Timeline
- 2026-06-09: patched: Fix merged into main branch via PR #2720
- 2026-06-23: disclosed: CVE-2026-56693 published