Impact
A bug in HKUDS nanobot allows remote attackers to manipulate the connect_mcp_servers function in the MCP enabledTools Scope Handler, causing improper access control that lets them register MCP resources outside the intended scope. This flaw can be exploited remotely and an exploit is publicly available, giving attackers the ability to gain unauthorized access to the MCP subsystem.
Affected Systems
All releases of HKUDS nanobot through version 0.2.1 are affected. The issue is fixed in 0.3.0, which developers recommend upgrading to. The vulnerability resides in nanobot/agent/tools/mcp.py of the MCP enabledTools component.
Risk and Exploitability
The CVSS score is 5.1, indicating moderate impact. Though the EPSS metric is unavailable, the public nature of the exploit and the remote attack vector increase the risk to environments that expose the MCP endpoint. The vulnerability is not listed in the CISA KEV catalog, but the lack of an EPSS score does not absolve the need for remediation.
OpenCVE Enrichment