PT-2026-51529 · Nanoclaw · Nanoclaw
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
NanoClaw versions prior to 2.1.17
Description
A privilege escalation issue exists in the
handleApprovalsResponse() function. The system fails to verify the authorization of the responder role, allowing attackers who possess a valid questionId to approve or reject privileged actions, such as package installations, by submitting approval response payloads.Recommendations
Update to version 2.1.17 or later.
As a temporary mitigation, restrict access to the
handleApprovalsResponse() function to authorized users only.Exploit
Fix
LPE
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nanoclaw