漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
nanocoai NanoClaw add_mcp_server request.ts handleAddMcpServer improper authorization
Vulnerability Description
A flaw has been found in nanocoai NanoClaw up to 2.0.64. Affected is the function handleAddMcpServer of the file src/modules/self-mod/request.ts of the component add_mcp_server. Executing a manipulation can lead to improper authorization. The attack may be launched remotely. The exploit has been published and may be used. This patch is called e5b928783d5c485637565eb07d2967922dfbf8d8. A patch should be applied to remediate this issue.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
授权机制不恰当
Vulnerability Title
NanoCo NanoClaw 权限许可和访问控制问题漏洞
Vulnerability Description
NanoCo NanoClaw是NanoCo组织的一个轻量级个人AI代理平台。 NanoCo NanoClaw 2.0.64及之前版本存在安全漏洞,该漏洞源于对src/modules/self-mod/request.ts文件中函数handleAddMcpServer的操作,可能导致授权不当。
CVSS Information
N/A
Vulnerability Type
N/A