PT-2026-40104 · Junoclaw · Junoclaw

CVE-2026-43992

·

Published

2026-05-12

·

Updated

2026-05-12

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions JunoClaw versions prior to 0.x.y-security-1
Description Every MCP write tool, including send tokens(), execute contract(), instantiate contract(), upload wasm(), and ibc transfer(), accepted mnemonic as an explicit tool-call parameter. This caused the BIP-39 seed (a standardized way to generate deterministic keys from a mnemonic phrase) to be embedded in the LLM tool-call JSON, exposing it to transport, log, or telemetry surfaces between the LLM provider and the MCP process.
Recommendations Update to version 0.x.y-security-1.

Exploit

Fix

Insertion into Log File

Cleartext Storage of Sensitive Information

Insufficiently Protected Credentials

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-43992
GHSA-J75Q-8XVM-6C48

Affected Products

Junoclaw