CVE-2026-17433: Improper authorization in nanocoai NanoClaw
A vulnerability in nanocoai NanoClaw up to version 2.0.64 allows improper authorization through manipulation of the createChatSdkBridge.setup function in the MCP Server Approval component. The exploit is now public and requires local access.
Disclosed 26 July 2026 · Record updated 13 September 2026
Impact
Improper authorization in MCP Server Approval component affecting NanoClaw versions up to 2.0.64
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-17433
