Echo eliminates 1,400 CVEs in NanoClaw's container images

We eliminated 1,400 CVEs in NanoClaw's container images

Echo eliminates 1,400 CVEs in NanoClaw's container images

Echo's partnership with NanoClaw aims to harden the open-source project's container images. By using multiple scanners, they identified over 1,400 CVEs, then systematically bumped safe upgrades, backported critical fixes, and leveraged Echo OS to patch OS-level vulnerabilities. The result: a 99% reduction in CVEs, with remaining ones continuously monitored. This post details the process, including a complex backport of CVE-2025-59375 in expat, showcasing Echo's AI-driven patching agents and commitment to upstream compatibility.

The final patch is 9 files, 64 hunks, +786/-112, with the complete upstream test suite passing.

More from this day

2026-08-13