Back to overview

CVE-2026-17433

MEDIUM
5.3
CVSS 3.1
Description
A vulnerability was detected in nanocoai NanoClaw up to 2.0.64. This impacts the function createChatSdkBridge.setup of the file src/channels/chat-sdk-bridge.ts of the component MCP Server Approval. Performing a manipulation results in improper authorization. The attack needs to be approached locally. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Metadata

CVE ID
CVE-2026-17433
State
PUBLISHED
Assigner
VulDB
Reserved
2026-07-25 11:08 UTC
Published
2026-07-26 02:30 UTC
Last updated
2026-07-26 02:30 UTC
Primary CWE
CWE-285
Improper Authorization
Vendor / Product
nanocoai / NanoClaw
Sources
cve.org  ·  NVD

Severity & Metrics

5.3 MEDIUM CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
Affected products (1)
VendorProductPlatformVersions
nanocoai NanoClaw 2.0.0, 2.0.1, 2.0.2, 2.0.3 …
Weakness (CWE)
CWESourceDescription
CWE-266 cna Incorrect Privilege Assignment
CWE-285 cna Improper Authorization
CVSS scores (4)
ScoreSeverityVersionSourceVector
5.3 MEDIUM 3.1 cna CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
5.3 MEDIUM 3.0 cna CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
4.8 MEDIUM 4.0 cna CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
4.3 N/D 2.0 cna AV:L/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR
References (6)
Back to overview