Description
A vulnerability was determined in HKUDS nanobot up to 0.2.1. Impacted is the function ExecTool._guard_command/ExecTool._spawn of the file nanobot/agent/tools/shell.py of the component ExecTool. This manipulation causes incomplete blacklist. It is possible to initiate the attack remotely. Patch name: af582246f141311d574551b7571a517bcc3df750. Applying a patch is the recommended action to fix this issue.
Published: 2026-09-14
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Command Execution
Action: Apply Patch
AI Analysis

Impact

The flaw resides in nanobot’s ExecTool._guard_command and ExecTool._spawn functions. Incomplete blacklist allows crafted commands to bypass filtering, which, as suggested in the description, could enable execution of arbitrary commands on the host, potentially compromising confidentiality and integrity. The weakness is an input validation failure, as identified by CWE‑183 and CWE‑184.

Affected Systems

The vulnerability affects HKUDS Nanobot versions up to and including 0.2.1. No additional vendors or product lines are listed as impacted. Running a version newer than 0.2.1 would eliminate the flaw if an update had been released.

Risk and Exploitability

Based on the description, it is inferred that attackers can exploit the flaw remotely by interacting with the ExecTool service, leveraging the incomplete blacklist to inject and run malicious commands. The CVSS score of 5.3 indicates a moderate risk. An EPSS score is not available, and the flaw is not catalogued in C KEV.

Generated by OpenCVE AI on September 15, 2026 at 13:13 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the patch commit af582246f141311d574551b7571a517bcc3df750 to the nanobot source or distribution.
  • Restrict network access to the ExecTool service so that only trusted hosts can reach it, for example by using firewall rules or placing the agent in a segregated network segment.
  • Review and harden the ExecTool._spawn and ExecTool._guard_command functions to ensure all prohibited commands are properly blocked.

Generated by OpenCVE AI on September 15, 2026 at 13:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in HKUDS nanobot up to 0.2.1. Impacted is the function ExecTool._guard_command/ExecTool._spawn of the file nanobot/agent/tools/shell.py of the component ExecTool. This manipulation causes incomplete blacklist. It is possible to initiate the attack remotely. Patch name: af582246f141311d574551b7571a517bcc3df750. Applying a patch is the recommended action to fix this issue.
Title HKUDS nanobot ExecTool shell.py ExecTool._spawn incomplete blacklist
First Time appeared Nanobot
Nanobot nanobot
Weaknesses CWE-183
CWE-184
CPEs cpe:2.3:a:nanobot:nanobot:*:*:*:*:*:*:*:*
Vendors & Products Nanobot
Nanobot nanobot
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:ND/RL:OF/RC:C'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-14T19:13:22.152Z

Reserved: 2026-09-13T16:10:33.299Z

Link: CVE-2026-90808

cve-icon Vulnrichment

Updated: 2026-09-14T19:13:13.452Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T19:18:10.700

Modified: 2026-09-14T20:56:48.220

Link: CVE-2026-90808

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T13:15:18Z

Weaknesses
  • CWE-183

    Permissive List of Allowed Inputs

  • CWE-184

    Incomplete List of Disallowed Inputs