HKUDS nanobot before 0.3.0 contains a server-side request forgery vulnerability in the WebFetchTool component where the _validate_url() function fails to block internal IP ranges and private addresses. Attackers can send messages instructing the bot to fetch cloud metadata endpoints, localhost services, and RFC 1918 addresses to extract IAM credentials and internal service data.
References
Configurations
No configuration.
History
17 Sep 2026, 14:17
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/HKUDS/nanobot/security/advisories/GHSA-vc5v-6vwm-wf9m - |
16 Sep 2026, 22:18
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-09-16 22:18
Updated : 2026-09-17 14:17
NVD link : CVE-2026-92576
Mitre link : CVE-2026-92576
CVE.ORG link : CVE-2026-92576
JSON object : View
Products Affected
No product.
CWE
CWE-918
Server-Side Request Forgery (SSRF)
