JunoClaw agentic AI platform patches three MCP tool vulnerabilities
Three CVEs in JunoClaw, an agentic AI platform built on Juno Network, covered an unvalidated filesystem path in the upload_wasm MCP tool, a bypassable substring blocklist in plugin-shell allowing unauthorized host command execution, and MCP write tools that accepted a BIP-39 mnemonic as a tool-call parameter, exposing the seed to transports, logs and telemetry. All were fixed in release 0.x.y-security-1.
Disclosed 12 May 2026 · Record updated 13 September 2026
Impact
Potential exposure of wallet seed phrases in LLM tool-call JSON, arbitrary file upload via unvalidated paths, and unauthorized command execution on the host when chained with the companion advisory.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-43989
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-43991
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-43992
