Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

CVE-2026-17433: Improper authorization in nanocoai NanoClaw

A vulnerability in nanocoai NanoClaw up to version 2.0.64 allows improper authorization through manipulation of the createChatSdkBridge.setup function in the MCP Server Approval component. The exploit is now public and requires local access.

Disclosed 26 July 2026 · Record updated 13 September 2026

Impact

Improper authorization in MCP Server Approval component affecting NanoClaw versions up to 2.0.64

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-17433