Server-Side Request Forgery Vulnerability in HKUDS Nanobot
CVE-2026-92576

9.2CRITICAL

Key Information:

Vendor

Hkuds

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-92576?

The HKUDS Nanobot prior to version 0.3.0 has a server-side request forgery (SSRF) vulnerability within the WebFetchTool component. This flaw arises from the _validate_url() function's failure to adequately check and block internal IP ranges and private addresses. An attacker could exploit this vulnerability to send malicious messages, instructing the bot to request data from cloud metadata endpoints, localhost services, and other RFC 1918 addresses, potentially exposing IAM credentials and accessing sensitive internal service data.

Affected Version(s)

nanobot 0 < 0.3.0

nanobot 0.3.0

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

zdi-disclosures
.