NanoClaw < 2.1.0 - Privilege Escalation via Forged Channel Approval Callback
No sign of exploitation. No public exploitation artifact known so far.
NanoClaw before version 2.1.0 allows administrators with limited permissions to trick the system into connecting messaging channels to groups they shouldn't have access to, potentially exposing restricted activities to unauthorized monitoring or control.
The vulnerability exists in the channel-registration approval flow where handleChannelApprovalResponse does not properly verify that an admin has appropriate privileges over target agent groups. Scoped admins can submit forged or stale callback values to establish messaging channels within out-of-scope agent groups, bypassing intended access controls and enabling unauthorized observation or control of restricted group operations.