PT-2026-51532 · Nanoclaw · Nanoclaw
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
NanoClaw versions prior to 2.1.0
Description
A privilege escalation issue exists in the channel-registration approval flow. The
handleChannelApprovalResponse() function fails to validate whether an administrator has the necessary privileges over the target agent groups. This allows scoped admins to submit forged or stale connect callback values to link messaging channels to agent groups outside their scope, potentially leading to unauthorized observation or control of restricted agent group activity.Recommendations
Update NanoClaw to version 2.1.0 or later.
As a temporary mitigation, restrict the use of the
handleChannelApprovalResponse() function for scoped administrators.Exploit
Fix
LPE
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nanoclaw