Impact
A flaw in the handleAddMcpServer function of the NanoClaw add_mcp_server module allows attackers to bypass normal authorization controls, enabling them to add or modify MCP server configurations. This improper authorization issue corresponds to CWE-266 and CWE-285 and may lead to unauthorized network access or data exposure.
Affected Systems
The vulnerability impacts nanocoai NanoClaw versions up to and including 2.0.64. Any installation of NanoClaw from the vendor prior to the patched release is vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity and the EPSS score of less than 1% suggests a low probability of exploitation in the wild, although an exploit has already been published and can be launched remotely. The issue is not listed in the CISA KEV catalog, but the remote nature of the attack and the availability of exploitation code warrant prompt action to prevent unauthorized server configuration changes.
OpenCVE Enrichment