What is CVE-2026-17434?
CVE-2026-17434 is an improper authorization flaw in the `handleAddMcpServer` function within `src/modules/self-mod/request.ts` of nanocoai NanoClaw up to version 2.0.64. This vulnerability allows remote manipulation, potentially leading to unauthorized actions. Users should apply the available patch or update immediately.
Azərbaycanca: CVE-2026-17434 nanocoai NanoClaw platformasının 2.0.64 versiyasına qədər olan versiyalarında `request.ts` faylındakı `handleAddMcpServer` funksiyasında aşkar edilmiş səlahiyyət yoxlaması (improper authorization) zəifliyidir. Bu boşluq uzaqdan icazəsiz əməliyyatlar aparmağa imkan verir. NanoClaw istifadəçiləri dərhal mövcud yamaq və ya yeniləməni tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-863; shared vendor: nanocoai
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.