CVE-2026-92576

HKUDS nanobot before 0.3.0 contains a server-side request forgery vulnerability in the WebFetchTool component where the _validate_url() function fails to block internal IP ranges and private addresses. Attackers can send messages instructing the bot to fetch cloud metadata endpoints, localhost services, and RFC 1918 addresses to extract IAM credentials and internal service data.
Configurations

No configuration.

History

17 Sep 2026, 14:17

Type Values Removed Values Added
References () https://github.com/HKUDS/nanobot/security/advisories/GHSA-vc5v-6vwm-wf9m - () https://github.com/HKUDS/nanobot/security/advisories/GHSA-vc5v-6vwm-wf9m -

16 Sep 2026, 22:18

Type Values Removed Values Added
New CVE

Information

Published : 2026-09-16 22:18

Updated : 2026-09-17 14:17


NVD link : CVE-2026-92576

Mitre link : CVE-2026-92576

CVE.ORG link : CVE-2026-92576


JSON object : View

Products Affected

No product.

CWE
CWE-918

Server-Side Request Forgery (SSRF)