nanoclaw vulnerability

NanoClaw before 2.1.17 contains a privilege escalation vulnerability in the handleApprovalsResponse function that fails to verify responder role authorization. Attackers with a valid questionId can approve or reject privileged actions like package installation by submitting approval response payloads without proper role validation.

Published 23 Jun 2026Updated 17 Sep 20264 sources
CVSS 7.1

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.