Vulnerability  ·  2026-08-09

HKUDS nanobot — MCP enabledTools scope handler improper access control

VulnerabilityMedium impactGlobalCVE-2026-19244
NVD published CVE-2026-19244 (CVSS 4.7, Medium) on August 7, 2026, describing an MCP tool-scope access-control failure in nanobot.
An MCP tool-scoping bypass means an agent could invoke tools outside its intended enabled set, undermining a core least-privilege control for MCP-based agent deployments, though blast radius is limited by the package's narrow adoption.
The connect_mcp_servers function in nanobot/agent/tools/mcp.py fails to properly enforce the enabledTools scope, resulting in improper access control that can be remotely triggered.
HKUDS nanobot up to version 0.2.1
Await vendor patch per referenced advisory; restrict MCP server connections to trusted tool sets in the interim.
NVD/CVE Record - CVE-2026-19244
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →