What is CVE-2026-19005?
CVE-2026-19005 is a vulnerability found in nanocoai NanoClaw up to version 2.0.64. It affects the handleCreateAgent function in src/modules/agent-to-agent/create-agent.ts, where improper privilege management can be exploited remotely via the Child-Agent Creation component. Users should check for a vendor-supplied security update.
Azərbaycanca: CVE-2026-19005 nanocoai NanoClaw 2.0.64-ə qədər versiyalarında aşkar edilmiş boşluqdur. src/modules/agent-to-agent/create-agent.ts faylındakı handleCreateAgent funksiyasında düzgün olmayan imtiyaz idarəetməsi səbəbindən remote hücumçu Child-Agent Creation komponenti vasitəsilə imtiyazları manipulyasiya edə bilər. NanoClaw istifadəçiləri vendor tərəfindən buraxılmış təhlükəsizlik yeniləməsini yoxlamalıdır.
Related CVEs
link basis: same weakness class CWE-269
FAQ2
Which versions of NanoClaw are affected by CVE-2026-19005?
This vulnerability affects nanocoai NanoClaw up to version 2.0.64.
Which component is targeted in CVE-2026-19005?
The vulnerability stems from improper privilege management in the `handleCreateAgent` function within `src/modules/agent-to-agent/create-agent.ts`, allowing a remote attacker to manipulate privileges via the Child-Agent Creation component.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.