CVE-2026-19244 | HKUDS nanobot up to 0.2.1 MCP enabledTools Scope mcp.py connect_mcp_servers access control (Issue 4435 / ID 4436)

SecurityVulns

A vulnerability identified as critical has been detected in HKUDS nanobot up to 0.2.1. The affected element is the function connect_mcp_servers of the file nanobot/agent/tools/mcp.py of the component MCP enabledTools Scope Handler. Performing a manipulation results in improper access controls.

This vulnerability is reported as CVE-2026-19244. The attack is possible to be carried out remotely. Moreover, an exploit is present.

You should upgrade the affected component.

Multiple issues were reported to the project. They reacted with a high level of professionalism and kindness: “Both reports describe the same root cause: MCP resource and prompt wrappers could be registered outside the intended enabledTools scope. The registration boundary was corrected”.VulDB Recent EntriesRead More