Executive brief
nanocoai NanoClaw, a tool for running AI agents in secure containers, contains a flaw in how it handles administrative approvals for new server connections. An attacker-controlled agent can trick an administrator into approving a seemingly safe server connection while secretly including hidden commands or environment variables. If approved, these hidden settings are saved and executed, allowing the agent to bypass security boundaries and potentially gain unauthorized access to the host system.
Technical details
An improper authorization vulnerability exists in NanoClaw's `handleAddMcpServer` function within `src/modules/self-mod/request.ts`. The application implements an approval flow for adding Model Context Protocol (MCP) servers, but the human-readable approval prompt only renders the `name` and `command` fields. An attacker-controlled agent can submit a request containing malicious `args` and `env` fields which are hidden from the approver but remain part of the persisted payload. Upon approval, `applyAddMcpServer` persists these hidden fields into the runtime configuration (`container.json`), leading to unauthorized command execution or environment manipulation. The issue was addressed in commit e5b9287 by splitting the handler into validation and hold-builder phases that ensure all payload components are properly capped and rendered for the approver.
Affected products
- nanocoai NanoClaw up to 2.0.64
Timeline
- 2026-07-13: patched: Fix merged in commit e5b928783d5c485637565eb07d2967922dfbf8d8
- 2026-07-26: advisory: CVE published via VulDB/NVD
References
- https://github.com/nanocoai/nanoclaw/
- https://github.com/nanocoai/nanoclaw/commit/e5b928783d5c485637565eb07d2967922dfbf8d8
- https://github.com/nanocoai/nanoclaw/issues/2762
- https://github.com/nanocoai/nanoclaw/pull/2998
- https://vuldb.com/cve/CVE-2026-17434
- https://vuldb.com/submit/862451
- https://vuldb.com/vuln/383075