PT-2026-69139 · Hkuds · Nanobot

·

CVE-2026-19244

·

Published

2026-08-07

·

Updated

2026-08-07

CVSS v2.0

5.8

Medium

VectorAV:N/AC:L/Au:M/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions HKUDS nanobot versions prior to 0.3.0
Description Improper access controls exist within the MCP enabledTools Scope Handler component. The issue resides in the connect mcp servers() function located in the nanobot/agent/tools/mcp.py file. This flaw allows MCP resource and prompt wrappers to be registered outside the intended enabledTools scope, enabling a remote attacker to perform unauthorized manipulations.
Recommendations Upgrade to version 0.3.0.

Exploit

Fix

Improper Access Control

Incorrect Privilege Assignment

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19244

Affected Products

Nanobot