CVE-2026-90809

A vulnerability was identified in HKUDS nanobot up to 0.2.1. The affected element is the function ExecTool._guard_command/ExecTool._spawn of the file nanobot/agent/tools/shell.py of the component ExecTool. Such manipulation leads to argument injection. It is possible to launch the attack remotely. The name of the patch is af582246f141311d574551b7571a517bcc3df750. It is best practice to apply a patch to resolve this issue.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-14 19:18

Updated : 2026-09-15 14:17


NVD link : CVE-2026-90809

Mitre link : CVE-2026-90809

CVE.ORG link : CVE-2026-90809


JSON object : View

Products Affected

No product.

CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-88

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')