CVE-2026-17434 | nanocoai NanoClaw up to 2.0.64 add_mcp_server request.ts handleAddMcpServer improper authorization (Issue 2762)

SecurityVulns

A vulnerability was found in nanocoai NanoClaw up to 2.0.64. It has been declared as critical. Affected is the function handleAddMcpServer of the file src/modules/self-mod/request.ts of the component add_mcp_server. Executing a manipulation can lead to improper authorization.

The identification of this vulnerability is CVE-2026-17434. The attack may be launched remotely. Furthermore, there is an exploit available.

A patch should be applied to remediate this issue.VulDB Recent EntriesRead More