Multiple CVE Vulnerabilities Disclosed in 2026 Affecting Various AI Platforms
Sourced from 1 publication
- •CVE-2026-18991 affects nanocoai NanoClaw and leads to path traversal through the sendfile component.
- •LettaBot 0.2.0 experiences missing authentication issues, described by CVE-2026-18990, allowing remote exploitation.
- •NousResearch hermes-agent up to 0.16.0 has incorrect privilege assignments, covered by CVE-2026-18976.
- •nearai ironclaw up to 0.29.1 faces command injection threats as identified by CVE-2026-18980.
Sources
Curated from 1 sources. Every summary is reviewed for accuracy, but may still contain errors. We always link to original sources for verification.
Related Stories
About Meridian
Meridian is a free daily newsletter delivering signal-scored news stories with forward-looking analysis every morning. Stories are scored across six criteria (global leverage, capital impact, temporal durability, career relevance, decision utility, and narrative clarity) then assigned to Big Signal, Core, or Quick tiers.
Get Meridian in your inbox
The stories that matter, every morning at 06:00.