CVE-2026-17433Medium· 5.3▾ SunlitA vulnerability was detected in nanocoai NanoClaw up to 2.0.64. This impacts the function createChatSdkBridge.setup of the file src/channels/chat-sdk-bridge.ts of the component MCP Server Approval. Performing a manipulation results in im…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 26.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.1%
A vulnerability was detected in nanocoai NanoClaw up to 2.0.64. This impacts the function createChatSdkBridge.setup of the file src/channels/chat-sdk-bridge.ts of the component MCP Server Approval. Performing a manipulation results in improper authorization. The attack needs to be approached locally. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-17434Medium· 6.3A flaw has been found in nanocoai NanoClaw up to 2.0.64
CVE-2026-93961Medium· 5.3A security flaw has been discovered in Dromara UJCMS up to 12.3.1
CVE-2026-2015Medium· 6.3A weakness has been identified in Portabilis i-Educar up to 2.10
CVE-2026-90810Medium· 6.3A security flaw has been discovered in cosmicstack-labs mercury-agent up to 1.1.13
CVE-2026-90499Medium· 5.4A security flaw has been discovered in lenve vhr 1.0-SNAPSHOT
CVE-2026-90520Medium· 6.3A vulnerability has been found in jaychouchannel Tourism-Management-System up to 84d8ec384f669df3985293dab293bb7b477efa64