Vulnerability  ·  2026-07-28

NanoClaw — Improper Authorization in MCP Server Approval Flow (chat-sdk-bridge)

VulnerabilityMedium impactGlobalCVE-2026-17433
NVD published CVE-2026-17433 (CVSS 5.0, Medium) on 2026-07-26, describing an improper-authorization vulnerability in NanoClaw's MCP server approval bridge that could allow a local attacker to bypass approval controls for MCP tool/server registration.
MCP server approval gates are the primary control preventing an agent from silently gaining new tool capabilities; a bypass here means an attacker with local access could get unapproved MCP servers/tools registered into a running agent session, expanding its capability surface without user consent — though the local-access requirement limits blast radius to a single niche project.
The createChatSdkBridge.setup function in src/channels/chat-sdk-bridge.ts (MCP Server Approval component) contains an improper-authorization flaw. Exploitation requires local access, per the NVD record, and manipulation of the approval flow could allow an MCP server to be approved/invoked without proper authorization checks.
nanocoai NanoClaw up to 2.0.64
Monitor the nanocoai/nanoclaw repository for a patched release; restrict local access to hosts running NanoClaw until a fix is available.
NVD - CVE-2026-17433
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →