CVE-2026-90808 Details
Description
A vulnerability was determined in HKUDS nanobot up to 0.2.1. Impacted is the function ExecTool._guard_command/ExecTool._spawn of the file nanobot/agent/tools/shell.py of the component ExecTool. This manipulation causes incomplete blacklist. It is possible to initiate the attack remotely. Patch name: af582246f141311d574551b7571a517bcc3df750. Applying a patch is the recommended action to fix this issue.
A vulnerability in HKUDS Nanobot versions through 0.2.1 allows for unintended command execution via the ExecTool component. The issue arises from an incomplete allowlist validation in the command handling process, specifically within the ExecTool._guard_command and ExecTool._spawn functions in nanobot/agent/tools/shell.py. This vulnerability can be exploited remotely through the OpenAI-compatible API.
Users can update to Nanobot version 0.3.5 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 14, 2026CISA-ADP
Assessed Sep 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/HKUDS/nanobot/issues/5305 | CISA-ADP | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/HKUDS/nanobot/ | [email protected] | ProductVendor |
| https://github.com/HKUDS/nanobot/commit/af582246f141311d574551b7571a517bcc3df750 | [email protected] | Source CodeVendor |
| https://github.com/HKUDS/nanobot/issues/5305 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/HKUDS/nanobot/pull/5345 | [email protected] | Issue TrackingVendor |
| https://vuldb.com/cve/CVE-2026-90808 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/922849 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/403310 | [email protected] | BundlePermission Required |
| https://vuldb.com/vuln/403310/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-183 | Permissive List of Allowed Inputs | [email protected] |
| CWE-184 | Incomplete List of Disallowed Inputs | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| HKUDS nanobot | <= 0.2.1 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 14, 2026 | New CVE Received | [email protected] |
| Sep 14, 2026 | CVE Modified | CISA-ADP |
Volerion