CVE-2026-43993

high

Description

JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, the WAVS bridge's computeDataVerify called fetch() on agent-supplied URLs without validating scheme, port, or resolved IP, resulting in an SSRF vulnerability. This vulnerability is fixed in 0.x.y-security-1.

References

https://github.com/Dragonmonk111/junoclaw/security/advisories/GHSA-q545-mvjf-q9pg

https://github.com/Dragonmonk111/junoclaw/releases/tag/v0.x.y-security-1

https://github.com/Dragonmonk111/junoclaw/commit/a168608

Details

Source: Mitre, NVD

Published: 2026-05-12

Updated: 2026-05-13

Risk Information

CVSS v2

Base Score: 8.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:P

Severity: High

CVSS v3

Base Score: 8.2

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:L

Severity: High

EPSS

EPSS: 0.00037