Skip to main content

Threats Tagged 'cve-2026-19244'

View all threats tagged with 'cve-2026-19244'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2026-19244

Threats Tagged 'cve-2026-19244'

Click on any threat for detailed analysis and mitigation recommendations

A vulnerability in HKUDS nanobot up to version 0.2.1 allows improper access control due to a flaw in the connect_mcp_servers function. This issue can be exploited remotely and has a public exploit available. The vulnerability is fixed by upgrading to version 0.3.0, which corrects the registration boundary of MCP resource and prompt wrappers to prevent unauthorized access.

Join the discussion

A vulnerability was detected in HKUDS nanobot up to 0.2.1. The affected element is the function connect_mcp_servers of the file nanobot/agent/tools/mcp.py of the component MCP enabledTools Scope Handler. Performing a manipulation results in improper access controls. The attack is possible to be carried out remotely. The exploit is now public and may be used. Upgrading to version 0.3.0 is sufficient to fix this issue. The patch is named 4436. You should upgrade the affected component. Multiple issues were reported to the project. They reacted with a high level of professionalism and kindness: "Both reports describe the same root cause: MCP resource and prompt wrappers could be registered outside the intended enabledTools scope. The registration boundary was corrected".

Join the discussion

Showing 1 to 2 of 2 results

Filters:Tag: cve-2026-19244
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses