CVE-2026-17434
Severity CVSS v4.0:
LOW
Type:
Unavailable / Other
Publication date:
26/07/2026
Last modified:
26/07/2026
Description
A flaw has been found in nanocoai NanoClaw up to 2.0.64. Affected is the function handleAddMcpServer of the file src/modules/self-mod/request.ts of the component add_mcp_server. Executing a manipulation can lead to improper authorization. The attack may be launched remotely. The exploit has been published and may be used. This patch is called e5b928783d5c485637565eb07d2967922dfbf8d8. A patch should be applied to remediate this issue.
Impact
Base Score 4.0
2.10
Severity 4.0
LOW
Base Score 3.x
6.30
Severity 3.x
MEDIUM
Base Score 2.0
6.50
Severity 2.0
MEDIUM
References to Advisories, Solutions, and Tools
- https://github.com/nanocoai/nanoclaw/
- https://github.com/nanocoai/nanoclaw/commit/e5b928783d5c485637565eb07d2967922dfbf8d8
- https://github.com/nanocoai/nanoclaw/issues/2762
- https://github.com/nanocoai/nanoclaw/pull/2998
- https://vuldb.com/cve/CVE-2026-17434
- https://vuldb.com/submit/862451
- https://vuldb.com/vuln/383075
- https://vuldb.com/vuln/383075/cti



