Server-Side Request Forgery Vulnerability in Nanobot by HKUDS
CVE-2026-49138
5.3MEDIUM
What is CVE-2026-49138?
The Nanobot application, prior to version 0.2.1, contains a server-side request forgery (SSRF) vulnerability in its web_fetch tool. This flaw can be exploited by remote attackers who provide a URL that redirects to either a loopback or a private address through a 3xx Location header. The vulnerability takes advantage of the automatic HTTP redirect handling included in the httpx library, allowing attackers to bypass initial URL validations and send outbound requests to internal network hosts, potentially exposing sensitive internal data before the final URL resolution is confirmed.
Affected Version(s)
nanobot 0
