Echo与NanoClaw宣布达成合作,通过采用AI驱动的硬化流程在NanoClaw的容器镜像中消除了约1400个CVE漏洞,漏洞减少幅度达99%[1]。该工作利用Trivy、Grype和Wiz等多个独立扫描器进行漏洞检测[1],随后通过Chromium升级、版本研究和补丁回移三步策略进行修复[1]。
其中一个典型案例是CVE-2025-59375,这是一个heap内存耗尽漏洞,仅需约250 KiB的文档即可导致约800 MiB的内存分配,放大倍数达3300倍[1]。针对这一漏洞的补丁涉及9个文件、64个hunks以及+786/-112行的代码变更[1]。此外,Echo OS已在操作系统级别修复了超过110万个CVE[1]。
Echo and NanoClaw have announced a collaboration to remove approximately 1,400 security vulnerabilities from NanoClaw's container images through an AI-driven hardening process, achieving a 99% reduction in detected flaws [1]. The effort employed multiple independent vulnerability scanners—Trivy, Grype, and Wiz—to identify weaknesses across the container environment [1].
The remediation strategy combined three key approaches: upgrading Chromium components, conducting version research, and implementing backported patches to address complex vulnerabilities [1]. A notable example involved CVE-2025-59375, a heap memory exhaustion flaw where approximately 250 KiB of malicious documents could trigger roughly 800 MiB of memory allocation, representing an amplification factor of about 3,300 times [1]. Resolving this vulnerability required modifications across 9 files totaling 64 code hunks, with 786 lines added and 112 lines removed [1].
This initiative builds on Echo's broader security efforts, which have previously addressed over 1.1 million operating system-level CVEs [1].