CVE-2026-17433 | nanocoai NanoClaw up to 2.0.64 MCP Server Approval chat-sdk-bridge.ts createChatSdkBridge.setup improper authorization (Issue 2761)

SecurityVulns

A vulnerability was found in nanocoai NanoClaw up to 2.0.64. It has been classified as critical. This impacts the function createChatSdkBridge.setup of the file src/channels/chat-sdk-bridge.ts of the component MCP Server Approval. Performing a manipulation results in improper authorization.

This vulnerability was named CVE-2026-17433. The attack needs to be approached locally. In addition, an exploit is available.

The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More