nanocoai vulnerabilities
4 CVEs tracked
In our reporting, vendor nanocoai appears exclusively through its product NanoClaw, with versions up to 2.0.64 flagged for critical vulnerabilities. The main theme involves remote privilege escalation and unauthorized access, with improper authorization and privilege management flaws discovered in the MCP Server addition (handleAddMcpServer) and Child-Agent creation (handleCreateAgent) functions. The relevant CVEs include CVE-2026-17434, CVE-2026-17433, CVE-2026-18991 (path traversal), and CVE-2026-19005. Defenders should prioritize the remote file access risk posed by CVE-2026-18991 and the privilege escalation potential highlighted by CVE-2026-19005.
Azərbaycanca: Hesabatlarımızda vendor nanocoai-in yeganə məhsulu olan NanoClaw versiya 2.0.64-ə qədər kritik zəifliklərlə diqqət mərkəzindədir. Aşkarlanan əsas mövzu remote privilege escalation və unauthorized access imkanlarıdır; xüsusilə MCP Server əlavə etmə (handleAddMcpServer) və Child-Agent yaratma (handleCreateAgent) funksiyalarında improper authorization/privilege management zəiflikləri müəyyən edilib. Əlaqəli zəifliklər sırasına CVE-2026-17434, CVE-2026-17433, CVE-2026-18991 (path traversal) və CVE-2026-19005 daxildir. Müdafiəçilər xüsusilə CVE-2026-18991 səbəbilə remote file access riskini, eləcə də CVE-2026-19005 kontekstində privilege escalation ehtimalını nəzərə almalıdırlar.
This vendor's CVEs4
This hub is built from skopnix's own reporting on nanocoai: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.