What is CVE-2026-17433?
CVE-2026-17433 is an improper authorization vulnerability in the "createChatSdkBridge.setup" function of the MCP Server Approval component in nanocoai NanoClaw up to version 2.0.64. It can be exploited locally to perform unauthorized actions. Users should update NanoClaw to the latest patched version to mitigate this risk.
Azərbaycanca: CVE-2026-17433, nanocoai NanoClaw 2.0.64-ə qədər versiyalarda MCP Server Approval komponentində "createChatSdkBridge.setup" funksiyasında aşkarlanmış "improper authorization" zəifliyidir. Bu, lokal şəkildə istismar edilə bilər və icazəsiz əməliyyatlara yol aça bilər. Təhlükəsizlik tədbiri olaraq, NanoClaw tətbiqini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863; shared vendor: nanocoai
FAQ2
In which component of nanocoai NanoClaw was CVE-2026-17433 discovered, and which function does it affect?
It was discovered in the MCP Server Approval component, specifically in the 'createChatSdkBridge.setup' function.
What security measure should be taken to protect against CVE-2026-17433?
Users should update the NanoClaw application to the latest patched version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.