Impact
The vulnerability resides in HKUDS nanobot versions up to 0.2.1, specifically in the ExecTool._guard_command/ExecTool._spawn functions within nanobot/agent/tools/shell.py. The flaw arises from improper sanitization of arguments passed to the spawn routine, allowing a malicious user to inject arbitrary command-line arguments. This injection can lead to the execution of unintended commands on the host, compromising confidentiality, integrity, and availability of the affected system. The weakness is classified as CWE‑74 (Command Injection) and CWE‑88 (Argument Injection).
Affected Systems
The affected product is HKUDS nanobot, with all releases up to version 0.2.1 vulnerable. The precise product name is simply nanobot, and the issue was identified in the ExecTool component of the nanobot source distribution.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity, but the ability to trigger the injection remotely increases the operational risk to the system. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog; however, because the attack vector is remote and no authentication is explicitly mentioned, the potential for exploitation remains realistic in environments where the ExecTool is reachable over a network. The attack path leverages the execution of the _spawn method, which, if called by an unauthenticated or privileged user, can execute arbitrary commands through the injected arguments.
OpenCVE Enrichment