Description
A vulnerability was identified in HKUDS nanobot up to 0.2.1. The affected element is the function ExecTool._guard_command/ExecTool._spawn of the file nanobot/agent/tools/shell.py of the component ExecTool. Such manipulation leads to argument injection. It is possible to launch the attack remotely. The name of the patch is af582246f141311d574551b7571a517bcc3df750. It is best practice to apply a patch to resolve this issue.
Published: 2026-09-14
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in HKUDS nanobot versions up to 0.2.1, specifically in the ExecTool._guard_command/ExecTool._spawn functions within nanobot/agent/tools/shell.py. The flaw arises from improper sanitization of arguments passed to the spawn routine, allowing a malicious user to inject arbitrary command-line arguments. This injection can lead to the execution of unintended commands on the host, compromising confidentiality, integrity, and availability of the affected system. The weakness is classified as CWE‑74 (Command Injection) and CWE‑88 (Argument Injection).

Affected Systems

The affected product is HKUDS nanobot, with all releases up to version 0.2.1 vulnerable. The precise product name is simply nanobot, and the issue was identified in the ExecTool component of the nanobot source distribution.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate severity, but the ability to trigger the injection remotely increases the operational risk to the system. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog; however, because the attack vector is remote and no authentication is explicitly mentioned, the potential for exploitation remains realistic in environments where the ExecTool is reachable over a network. The attack path leverages the execution of the _spawn method, which, if called by an unauthenticated or privileged user, can execute arbitrary commands through the injected arguments.

Generated by OpenCVE AI on September 15, 2026 at 07:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the patch corresponding to commit af582246f141311d574551b7571a517bcc3df750 or upgrade to a nanobot version that incorporates this fix.
  • Ensure that the ExecTool command execution pathways are only invoked by trusted users and that any remote access to ExecTool is tightly controlled or disabled.
  • If the patch cannot be applied immediately, sanitize all arguments passed to ExecTool._spawn by validating or escaping them according to safer coding practices and restrict the tool’s usage through network firewall rules or access controls.

Generated by OpenCVE AI on September 15, 2026 at 07:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
First Time appeared Hkuds
Hkuds nanobot
Vendors & Products Hkuds
Hkuds nanobot

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in HKUDS nanobot up to 0.2.1. The affected element is the function ExecTool._guard_command/ExecTool._spawn of the file nanobot/agent/tools/shell.py of the component ExecTool. Such manipulation leads to argument injection. It is possible to launch the attack remotely. The name of the patch is af582246f141311d574551b7571a517bcc3df750. It is best practice to apply a patch to resolve this issue.
Title HKUDS nanobot ExecTool shell.py ExecTool._spawn argument injection
First Time appeared Nanobot
Nanobot nanobot
Weaknesses CWE-74
CWE-88
CPEs cpe:2.3:a:nanobot:nanobot:*:*:*:*:*:*:*:*
Vendors & Products Nanobot
Nanobot nanobot
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:ND/RL:OF/RC:C'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T13:56:20.021Z

Reserved: 2026-09-13T16:11:20.697Z

Link: CVE-2026-90809

cve-icon Vulnrichment

Updated: 2026-09-15T13:32:54.834Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T19:18:11.290

Modified: 2026-09-15T14:17:38.560

Link: CVE-2026-90809

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T08:00:16Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-88

    Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')