PT-2026-69139 · Hkuds · Nanobot
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:L/Au:M/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
HKUDS nanobot versions prior to 0.3.0
Description
Improper access controls exist within the MCP enabledTools Scope Handler component. The issue resides in the
connect mcp servers() function located in the nanobot/agent/tools/mcp.py file. This flaw allows MCP resource and prompt wrappers to be registered outside the intended enabledTools scope, enabling a remote attacker to perform unauthorized manipulations.Recommendations
Upgrade to version 0.3.0.
Exploit
Fix
Improper Access Control
Incorrect Privilege Assignment
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nanobot