CVE-2026-19246
- EPSS 0.22%
- Veröffentlicht 07.08.2026 21:00:14
- Zuletzt bearbeitet 14.08.2026 16:16:51
A vulnerability has been found in HKUDS nanobot up to 0.2.1. This affects the function _download_image_data_url of the file nanobot/providers/image_generation.py of the component Provider-returned Image URL Handler. The manipulation leads to server-s...
CVE-2026-19245
- EPSS 0.12%
- Veröffentlicht 07.08.2026 20:45:12
- Zuletzt bearbeitet 12.08.2026 20:59:21
A flaw has been found in HKUDS nanobot up to 0.2.1. The impacted element is the function ExecTool._prepare_command of the file nanobot/agent/tools/shell.py of the component Login-shell Environment Handler. Executing a manipulation can lead to informa...
CVE-2026-19244
- EPSS 0.27%
- Veröffentlicht 07.08.2026 20:30:13
- Zuletzt bearbeitet 12.08.2026 21:00:37
A vulnerability was detected in HKUDS nanobot up to 0.2.1. The affected element is the function connect_mcp_servers of the file nanobot/agent/tools/mcp.py of the component MCP enabledTools Scope Handler. Performing a manipulation results in improper ...
CVE-2026-19243
- EPSS 1.61%
- Veröffentlicht 07.08.2026 19:30:13
- Zuletzt bearbeitet 12.08.2026 20:59:21
A security vulnerability has been detected in HKUDS nanobot up to 0.2.1. Impacted is the function ExecTool._guard_command/ExecTool._spawn of the file nanobot/agent/tools/shell.py of the component Shell Allowlist Handler. Such manipulation leads to os...
CVE-2026-35589
- EPSS 0.16%
- Veröffentlicht 14.04.2026 22:47:32
- Zuletzt bearbeitet 24.07.2026 21:10:00
nanobot is a personal AI assistant. Versions prior to 0.1.5 contain a Cross-Site WebSocket Hijacking (CSWSH) vulnerability exists in the bridge's WebSocket server in bridge/src/server.ts, resulting from an incomplete remediation of CVE-2026-2577. The...
CVE-2026-33654
- EPSS 0.49%
- Veröffentlicht 27.03.2026 19:43:49
- Zuletzt bearbeitet 08.04.2026 15:19:02
nanobot is a personal AI assistant. Prior to version 0.1.6, an indirect prompt injection vulnerability exists in the email channel processing module (`nanobot/channels/email.py`), allowing a remote, unauthenticated attacker to execute arbitrary LLM i...