Server-Side Request Forgery Vulnerability in Nanobot by HKUDS
CVE-2026-49138

5.3MEDIUM

Key Information:

Vendor

Hkuds

Status
Vendor
CVE Published:
1 June 2026

What is CVE-2026-49138?

The Nanobot application, prior to version 0.2.1, contains a server-side request forgery (SSRF) vulnerability in its web_fetch tool. This flaw can be exploited by remote attackers who provide a URL that redirects to either a loopback or a private address through a 3xx Location header. The vulnerability takes advantage of the automatic HTTP redirect handling included in the httpx library, allowing attackers to bypass initial URL validations and send outbound requests to internal network hosts, potentially exposing sensitive internal data before the final URL resolution is confirmed.

Affected Version(s)

nanobot 0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Chia Min Jun Lennon
.