Skip to content

MCPA-2026-0020

lowoverprivilegedCVSS 4.7

HKUDS nanobot improper access controls in MCP enabledTools scope handler (CVE-2026-19244)

HKUDS nanobot (PyPI: nanobot-ai) up to 0.2.1 has improper access controls in connect_mcp_servers (nanobot/agent/tools/mcp.py, MCP enabledTools scope handler): the configured enabledTools scope is not enforced correctly, so tools outside the intended scope remain reachable, remotely exploitable with a public exploit. Upgrading to 0.3.0 fixes the issue (patch PR #4436).

Affected packages

EcosystemPackageAffected versions
pypinanobot-ai
>= 0, < 0.3.0

Identifiers

CVE-2026-19244GHSA-qwp6-wxvx-2jc8CWE-284

References

Timeline

  • Published: 2026-08-07

← All advisories