Description
HKUDS nanobot before 0.3.0 contains a server-side request forgery vulnerability in the WebFetchTool component where the _validate_url() function fails to block internal IP ranges and private addresses. Attackers can send messages instructing the bot to fetch cloud metadata endpoints, localhost services, and RFC 1918 addresses to extract IAM credentials and internal service data.
Published: 2026-09-16
Score: 9.2 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Server‑Side Request Forgery allowing extraction of internal credentials and data
Action: Immediate Patch
AI Analysis

Impact

The vulnerable WebFetchTool component in HKUDS nanobot, before version 0.3.0, contains a server‑side request forgery flaw where the internal URL validation routine does not reject private or internal address ranges. This allows an attacker controlling the bot’s message interface to instruct the tool to resolve and retrieve data from cloud metadata endpoints, localhost services, or RFC 1918 addresses, exposing IAM credentials and other sensitive internal information. The weakness is classified as CWEs involved in improper input validation for request handlers.

Affected Systems

All deployments of HKUDS nanobot running any release prior to 0.3.0 are vulnerable. No specific installation or configuration constraints are listed, so the impact applies to every instance of the product containing the affected component.

Risk and Exploitability

The nominal CVSS score is 9.2, indicating a high‐severity vulnerability. The EPSS score is reported as less than 1 %, which may reflect a low current exploitation probability or limited public data. The flaw is not listed in the CISA KEV catalog, but the impact and severity create a strong demand for remediation. An attacker could trigger the SSRF by sending a crafted message to the bot; the required preconditions are simply remote access to the bot’s API interface. If successful, the attacker can read internal service metadata and potentially obtain privileged credentials.

Generated by OpenCVE AI on September 17, 2026 at 23:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade HKUDS nanobot to version 0.3.0 or later, which removes the flawed URL validator.
  • If an upgrade is not immediately possible, limit the bot’s network traffic so that the WebFetchTool cannot resolve or reach internal IP ranges or localhost addresses, effectively blocking the SSRF path.
  • Disable or remove the WebFetchTool functionality until a patch is applied, preventing the attacker from triggering the vulnerable request handler.

Generated by OpenCVE AI on September 17, 2026 at 23:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description HKUDS nanobot before 0.3.0 contains a server-side request forgery vulnerability in the WebFetchTool component where the _validate_url() function fails to block internal IP ranges and private addresses. Attackers can send messages instructing the bot to fetch cloud metadata endpoints, localhost services, and RFC 1918 addresses to extract IAM credentials and internal service data.
Title HKUDS nanobot before 0.3.0 Server-Side Request Forgery via WebFetchTool
First Time appeared Nanobot
Nanobot nanobot
Weaknesses CWE-918
CPEs cpe:2.3:a:nanobot:nanobot:*:*:*:*:*:*:*:*
Vendors & Products Nanobot
Nanobot nanobot
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'}

cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T13:32:06.815Z

Reserved: 2026-09-16T13:47:20.116Z

Link: CVE-2026-92576

cve-icon Vulnrichment

Updated: 2026-09-17T13:32:02.826Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T22:18:27.757

Modified: 2026-09-17T14:17:54.510

Link: CVE-2026-92576

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T00:00:13Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)