Description
JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, the WAVS bridge's computeDataVerify called fetch() on agent-supplied URLs without validating scheme, port, or resolved IP, resulting in an SSRF vulnerability. This vulnerability is fixed in 0.x.y-security-1.
Problem types
CWE-918: Server-Side Request Forgery (SSRF)
Product status
References
github.com/...noclaw/security/advisories/GHSA-q545-mvjf-q9pg
github.com/Dragonmonk111/junoclaw/commit/a168608
github.com/...onk111/junoclaw/releases/tag/v0.x.y-security-1