Impact
The flaw resides in nanobot’s ExecTool._guard_command and ExecTool._spawn functions. Incomplete blacklist allows crafted commands to bypass filtering, which, as suggested in the description, could enable execution of arbitrary commands on the host, potentially compromising confidentiality and integrity. The weakness is an input validation failure, as identified by CWE‑183 and CWE‑184.
Affected Systems
The vulnerability affects HKUDS Nanobot versions up to and including 0.2.1. No additional vendors or product lines are listed as impacted. Running a version newer than 0.2.1 would eliminate the flaw if an update had been released.
Risk and Exploitability
Based on the description, it is inferred that attackers can exploit the flaw remotely by interacting with the ExecTool service, leveraging the incomplete blacklist to inject and run malicious commands. The CVSS score of 5.3 indicates a moderate risk. An EPSS score is not available, and the flaw is not catalogued in C KEV.
OpenCVE Enrichment