Impact
A vulnerability exists in the handleCreateAgent function of nanocoai NanoClaw, affecting versions up to 2.0.64. The flaw allows an attacker to manipulate the function to bypass proper privilege checks and create child agents with higher privileges than intended. This leads to unauthorized privilege escalation and could compromise the confidentiality and integrity of the system. The weakness is categorized as Authorization Bypass (CWE-266) and Improper Privilege Management (CWE-269).
Affected Systems
The affected product is nanocoai NanoClaw version 2.0.64 and earlier. The component in question is located in src/modules/agent-to-agent/create-agent.ts. Users relying on earlier releases of the software, especially those hosting the repository at https://github.com/nanocoai/nanoclaw/, are potentially exposed.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the description states that remote exploitation is possible and the exploit is publicly available, meaning that an attacker who can reach the exposed endpoint could potentially create privileged child agents without authorization. The risk therefore remains significant for deployments without prompt remediation.
OpenCVE Enrichment