Server-Side Request Forgery Vulnerability in HKUDS Nanobot
CVE-2026-92576
9.2CRITICAL
What is CVE-2026-92576?
The HKUDS Nanobot prior to version 0.3.0 has a server-side request forgery (SSRF) vulnerability within the WebFetchTool component. This flaw arises from the _validate_url() function's failure to adequately check and block internal IP ranges and private addresses. An attacker could exploit this vulnerability to send malicious messages, instructing the bot to request data from cloud metadata endpoints, localhost services, and other RFC 1918 addresses, potentially exposing IAM credentials and accessing sensitive internal service data.
Affected Version(s)
nanobot 0 < 0.3.0
nanobot 0.3.0
