Description
A flaw has been found in nanocoai NanoClaw up to 2.0.64. Affected is the function handleAddMcpServer of the file src/modules/self-mod/request.ts of the component add_mcp_server. Executing a manipulation can lead to improper authorization. The attack may be launched remotely. The exploit has been published and may be used. This patch is called e5b928783d5c485637565eb07d2967922dfbf8d8. A patch should be applied to remediate this issue.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Sun, 26 Jul 2026 04:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw has been found in nanocoai NanoClaw up to 2.0.64. Affected is the function handleAddMcpServer of the file src/modules/self-mod/request.ts of the component add_mcp_server. Executing a manipulation can lead to improper authorization. The attack may be launched remotely. The exploit has been published and may be used. This patch is called e5b928783d5c485637565eb07d2967922dfbf8d8. A patch should be applied to remediate this issue. | |
| Title | nanocoai NanoClaw add_mcp_server request.ts handleAddMcpServer improper authorization | |
| First Time appeared |
Nanocoai
Nanocoai nanoclaw |
|
| Weaknesses | CWE-266 CWE-285 |
|
| CPEs | cpe:2.3:a:nanocoai:nanoclaw:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Nanocoai
Nanocoai nanoclaw |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-07-26T03:00:16.981Z
Reserved: 2026-07-25T11:08:25.395Z
Link: CVE-2026-17434
No data.
No data.
No data.
OpenCVE Enrichment
No data.