CVE-2026-17434: nanocoai NanoClaw add_mcp_server request.ts handleAddMcpServer improper authorization
A flaw has been found in nanocoai NanoClaw up to 2.0.64. Affected is the function handleAddMcpServer of the file src/modules/self-mod/request.ts of the component addmcpserver. Executing a manipulation can lead to improper authorization. The attack may be launched remotely. The exploit has been published and may be used. This patch is called e5b928783d5c485637565eb07d2967922dfbf8d8. A patch should be applied to remediate this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
nanocoai NanoClaw add_mcp_server (src/modules/self-mod/request.ts - handleAddMcpServer)to a version that resolves this vulnerability.Patch e5b928783d5c485637565eb07d2967922dfbf8d8
Event History
Frequently Asked Questions
What is the severity of CVE-2026-17434?
CVE-2026-17434 has a medium severity rating of 6.3.
How do I fix CVE-2026-17434?
To fix CVE-2026-17434, update nanocoai NanoClaw to version 2.0.65 or later which addresses the improper authorization issue.
What vulnerability does CVE-2026-17434 present?
CVE-2026-17434 presents an improper authorization vulnerability in the handleAddMcpServer function of nanocoai NanoClaw.
Can CVE-2026-17434 be exploited remotely?
Yes, CVE-2026-17434 can be exploited remotely.
What components of nanocoai NanoClaw are affected by CVE-2026-17434?
The affected component is the add_mcp_server function found in src/modules/self-mod/request.ts.