Impact
The vulnerable WebFetchTool component in HKUDS nanobot, before version 0.3.0, contains a server‑side request forgery flaw where the internal URL validation routine does not reject private or internal address ranges. This allows an attacker controlling the bot’s message interface to instruct the tool to resolve and retrieve data from cloud metadata endpoints, localhost services, or RFC 1918 addresses, exposing IAM credentials and other sensitive internal information. The weakness is classified as CWEs involved in improper input validation for request handlers.
Affected Systems
All deployments of HKUDS nanobot running any release prior to 0.3.0 are vulnerable. No specific installation or configuration constraints are listed, so the impact applies to every instance of the product containing the affected component.
Risk and Exploitability
The nominal CVSS score is 9.2, indicating a high‐severity vulnerability. The EPSS score is reported as less than 1 %, which may reflect a low current exploitation probability or limited public data. The flaw is not listed in the CISA KEV catalog, but the impact and severity create a strong demand for remediation. An attacker could trigger the SSRF by sending a crafted message to the bot; the required preconditions are simply remote access to the bot’s API interface. If successful, the attacker can read internal service metadata and potentially obtain privileged credentials.
OpenCVE Enrichment