Tech Leverage

Multiple CVE Vulnerabilities Disclosed in 2026 Affecting Various AI Platforms

Sourced from 1 publication

  • CVE-2026-18991 affects nanocoai NanoClaw and leads to path traversal through the sendfile component.
  • LettaBot 0.2.0 experiences missing authentication issues, described by CVE-2026-18990, allowing remote exploitation.
  • NousResearch hermes-agent up to 0.16.0 has incorrect privilege assignments, covered by CVE-2026-18976.
  • nearai ironclaw up to 0.29.1 faces command injection threats as identified by CVE-2026-18980.

Sources

Was this story useful?

Curated from 1 sources. Every summary is reviewed for accuracy, but may still contain errors. We always link to original sources for verification.

Related Stories

About Meridian

Meridian is a free daily newsletter delivering signal-scored news stories with forward-looking analysis every morning. Stories are scored across six criteria (global leverage, capital impact, temporal durability, career relevance, decision utility, and narrative clarity) then assigned to Big Signal, Core, or Quick tiers.

Get Meridian in your inbox

The stories that matter, every morning at 06:00.