Impact
This vulnerability resides in the ExecTool._prepare_command function of the nanobot login‑shell environment handler. Manipulating the function allows an attacker to read confidential information that should be protected, such as environment variables initialized in login shells. The flaw is a direct data leak, corresponding to confidentiality impairment.
Affected Systems
The affected product is HKUDS nanobot, versions up to and including 0.2.1. The known vendor is HKUDS, and the product name is nanobot. The specific function located in nanobot/agent/tools/shell.py is impacted. Users running the compromised versions should update to at least 0.3.0.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate severity. The flaw requires local access, meaning it is exploitable only by users who can log into the system where the agent runs. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. The exploit has been published, so a local attacker with sufficient privileges can abuse it to disclose sensitive data. The lack of a higher score or broad attack vector suggests the threat is limited to the local environment.
OpenCVE Enrichment