JunoClaw Agentic AI Toolchain
MCP Wallet Seed Exposure, Shell Command Injection, and SSRF in a Blockchain Agent Platform
JunoClaw disclosed four vulnerabilities in its agentic AI platform on Juno Network. The most critical: every MCP write tool accepted a raw BIP-39 mnemonic as an explicit tool-call parameter, embedding the wallet seed in LLM tool-call JSON and exposing it to any transport, log, or telemetry surface between the LLM provider and the MCP process. Compounding this, a shell plugin permitted command injection via metacharacter bypass, and the WAVS bridge allowed SSRF via unvalidated URL fetching. All issues are addressed in @junoclaw/cosmos-mcp version 0.3.0 and later.
"Every MCP write tool ... accepted
mnemonic: stringas an explicit tool-call parameter. The BIP-39 seed was consequently embedded in the LLM tool-call JSON, exposing it to any transport, log, or telemetry surface in the path between the LLM provider and the MCP process."— GitHub Security Advisory GHSA-j75q-8xvm-6c48
Vulnerabilities
BIP-39 Mnemonic Serialized in LLM Tool-Call JSON
Every MCP write tool in the JunoClaw platform accepted a mnemonic: string parameter directly from the LLM invocation path. BIP-39 mnemonics are the root secret controlling all blockchain assets in a wallet — placing them in tool-call JSON exposes the seed to LLM provider telemetry, application traces, transport captures, MCP process logs, and any debugging surface in the full request path.
Shell Plugin — Unsafe Command Execution via Metacharacter Handling
The shell plugin wrapped agent-supplied commands in sh -c (Unix) or cmd /C (Windows), passing the full string to a shell interpreter. This allows shell metacharacter sequences (;, &&, |, $()) embedded in model-generated arguments to execute arbitrary host commands.
Shell Plugin — Command-Safety Blocklist Bypass
The command-safety mechanism employed a substring blocklist to detect dangerous commands. Adversarially constructed argument strings — such as inserting whitespace, Unicode normalization, or case variations — bypassed the blocklist checks while still being interpreted as the blocked command by the underlying shell. Substring blocklists are not a viable security primitive for command filtering.
WAVS Bridge — SSRF via Unvalidated URL in computeDataVerify
The WAVS bridge's computeDataVerify function called fetch() on agent-supplied URLs without validating scheme, port, or resolved IP address. An attacker who can influence the URLs submitted to this function can reach cloud metadata endpoints (169.254.169.254), internal services on RFC1918 ranges, or loopback interfaces — enabling credential exfiltration and internal network reconnaissance.
Attack Chain
Attacker Reaches the Agent Invocation Path
The attacker influences inputs that reach JunoClaw's MCP write tools, shell plugin calls, or the WAVS bridge URL verification function. This could be via prompt injection in untrusted data processed by the agent, a malicious user interacting with an exposed agent endpoint, or a compromised upstream tool in the chain.
No authentication bypass is required — the vulnerabilities are in how the tools handle inputs they legitimately receive.
Wallet Seed Leaks into the LLM Invocation Path
MCP write tools serialize the mnemonic: string parameter into LLM tool-call JSON. This JSON is transmitted to the LLM provider, recorded in application traces, written to MCP process logs, and potentially captured in debugging and observability infrastructure. Any party with access to these surfaces — including the LLM provider itself — receives the raw BIP-39 seed.
BIP-39 mnemonics are the root secret for all assets in the wallet. Exposure is equivalent to handing over the private key.
Shell Metacharacters Bypass Safety Checks
Separately, an attacker crafts shell arguments containing metacharacter sequences or adversarial string patterns that bypass the substring blocklist in CVE-2026-43991. The unsafe sh -c execution path in CVE-2026-43990 then interprets the constructed string as a compound shell command, executing arbitrary code on the host with agent runtime privileges.
The blocklist bypass (CVE-2026-43991) is the key step — without it, the injection (CVE-2026-43990) would be partially mitigated.
WAVS Bridge Reaches Internal Network via SSRF
Attacker-controlled URLs are submitted to the WAVS bridge's computeDataVerify function. Without scheme, port, or IP validation, the unguarded fetch() call reaches cloud metadata endpoints (e.g., 169.254.169.254) or internal services on private IP ranges, returning credential material or internal service responses to the attacker.
In cloud deployments, metadata endpoint access typically yields instance credentials with broader IAM permissions.
Combined Impact: Wallet Drain, Host Compromise, Network Pivot
Each vulnerability independently produces a severe outcome. Combined, they represent a platform-level compromise: wallet seeds leaked from logs are used to drain on-chain assets; shell injection provides host command execution for persistence and lateral movement; SSRF in the WAVS bridge enables cloud credential theft and internal network reconnaissance. The three attack surfaces can be exploited independently or chained.
Because these are design flaws rather than implementation bugs, all JunoClaw deployments running the affected version are vulnerable simultaneously.
Impact
BIP-39 mnemonics are irreplaceable root secrets — unlike API keys, wallet seeds cannot be rotated without moving all assets to a new wallet. The exposure surface created by serializing these secrets into LLM tool-call JSON is fundamentally architectural, not incidental.
Blockchain / Financial
- Complete wallet compromise from seed exposure
- Irreversible asset drain to attacker-controlled addresses
- All wallets sharing the exposed mnemonic at risk
- No recovery path without fund migration
Host / Infrastructure
- Arbitrary command execution on the agent host
- Persistence establishment via scheduled tasks or cron
- Lateral movement to co-hosted services
- Agent runtime process privileges fully inherited
Cloud / Network
- Cloud metadata endpoint access for IAM credential theft
- Internal service reconnaissance via SSRF
- Exfiltration of services not exposed to the internet
- Potential pivot to cloud control plane via stolen IAM keys
Defensive Tutorial
Upgrade to @junoclaw/cosmos-mcp 0.3.0 or later
ImmediateAll four CVEs are addressed in the v0.x.y-security-1 release, with @junoclaw/cosmos-mcp at version 0.3.0 or later as the minimum safe version. Upgrade before resuming any agent workflows that interact with wallet functions, shell tools, or the WAVS bridge.
Remove raw mnemonics from all tool configurations and prompts
ImmediateAudit every workflow definition, prompt template, and tool configuration for instances where a raw BIP-39 mnemonic phrase is passed as a parameter. Remove them immediately. Even after upgrading, mnemonic values that appeared in prior tool-call JSON may persist in LLM provider logs, telemetry, and your own application traces.
Rotate affected wallet mnemonics and migrate funds
ImmediateIf any wallet mnemonic was passed through an MCP tool-call in an affected version, treat that seed as compromised. Generate a new wallet with a freshly created BIP-39 seed — generated offline or in a hardware wallet — and transfer all assets immediately. Do not reuse the exposed seed phrase for any purpose.
Disable or sandbox the shell plugin
UrgentUntil the patched command execution and command-safety logic is deployed and verified, disable the shell plugin entirely or run it in a sandboxed environment (Docker container, VM, or seccomp-restricted process) where unauthorized commands cannot affect the host or network. Shell access from an LLM agent should be treated as a privileged capability requiring explicit justification.
Block cloud metadata endpoints and private ranges from agent runtimes
UrgentApply egress firewall rules or network policy to block agent runtime access to 169.254.169.254, RFC1918 ranges (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16), and loopback addresses. This neutralizes the SSRF vector even before the application-layer fix is in place, and is best-practice for any agent runtime regardless of this vulnerability.
Redesign wallet integration to use opaque wallet handles
ImportantThe architectural fix for CVE-2026-43992 is to never allow the model to see or pass raw seed material. Replace mnemonic: string parameters with opaque wallet_id: string handles resolved server-side against an encrypted wallet registry. The model passes an identifier; the signing operation occurs in a hardened boundary that the LLM never crosses.
Replace blocklist command safety with allowlisted argv execution
ImportantSubstring blocklists are not a viable security primitive for command filtering — they are bypassed by encoding, whitespace, and Unicode normalization. Replace them with: an allowlist of permitted executables, parsed argv arrays passed directly to execve without shell interpretation, and explicit rejection of any argument that cannot be validated against a known-safe pattern.
Validate scheme, port, and resolved IP for all URL-fetching tools
ImportantAny tool that calls fetch() or equivalent on an agent-supplied URL must resolve the hostname and validate the final IP before connecting. Deny loopback, link-local, RFC1918 private space, and cloud metadata IPs. Restrict schemes to https:// only unless a documented business requirement requires otherwise. This applies to all agent tools — not just the WAVS bridge.
Establish agent tool risk classification with privileged tool gates
ImportantWallet-signing, shell execution, file writing, network fetch, contract deployment, and token transfer tools are privileged capabilities that warrant separate review and stronger policy gates than read-only informational tools. Establish a formal risk classification for agent tools in your organization, require explicit approval to add privileged tools to any agent, and run privileged tools in dedicated isolated runtimes.
Implement telemetry hygiene for agent secret handling
ImportantAudit all logging, tracing, and telemetry pipelines for places where tool-call arguments are captured verbatim. Implement redaction rules that scrub known-sensitive parameter names — mnemonic, private_key, password, secret, token — before values reach any log sink. Govern LLM provider data retention and data-processing agreements to limit how long tool-call JSON is retained by the model provider.
References
- GitHub Security Advisory GHSA-j75q-8xvm-6c48 — JunoClaw / cosmos-mcp Multiple Vulnerabilities
-
CVE Program
CVE-2026-43992 (CVSS 9.8) — BIP-39 Mnemonic Serialized in LLM Tool-Call JSON
CVE-2026-43990 (CVSS 8.4) — Shell Command Injection via Metacharacter Handling
CVE-2026-43991 (CVSS 8.4) — Command-Safety Blocklist Bypass
CVE-2026-43993 (CVSS 8.2) — SSRF via Unvalidated URL in WAVS Bridge