VYPR
Medium severity6.5OSV Advisory· Published Jun 23, 2026· Updated Jun 23, 2026

CVE-2026-56402

CVE-2026-56402

Description

NanoClaw before 2.1.17 contains a privilege escalation vulnerability in the handleApprovalsResponse function that fails to verify responder role authorization. Attackers with a valid questionId can approve or reject privileged actions like package installation by submitting approval response payloads without proper role validation.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Nanocoai/NanoclawOSV2 versions
    v2.0.64, v2.0.63, v2.0.54, …+ 1 more
    • (no CPE)range: v2.0.64, v2.0.63, v2.0.54, …
    • (no CPE)range: <2.1.17

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.