CVE-2026-92576 Details
Description
HKUDS nanobot before 0.3.0 contains a server-side request forgery vulnerability in the WebFetchTool component where the _validate_url() function fails to block internal IP ranges and private addresses. Attackers can send messages instructing the bot to fetch cloud metadata endpoints, localhost services, and RFC 1918 addresses to extract IAM credentials and internal service data.
A server-side request forgery (SSRF) vulnerability has been identified in HKUDS Nanobot versions prior to 0.3.0, specifically within the WebFetchTool component. The vulnerability arises because the _validate_url() function does not properly restrict internal IP ranges and private addresses. This oversight allows attackers to send messages that instruct the bot to retrieve data from cloud metadata endpoints, localhost services, and RFC 1918 private addresses. Such actions could lead to the extraction of IAM credentials and internal service information.
Users are advised to update to HKUDS Nanobot version 0.3.0 or later, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 16, 2026CISA-ADP
Assessed Sep 17, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/HKUDS/nanobot/security/advisories/GHSA-vc5v-6vwm-wf9m | CISA-ADP | AdvisoryExploitRemedyVendor |
| https://github.com/HKUDS/nanobot/security/advisories/GHSA-vc5v-6vwm-wf9m | [email protected] | AdvisoryExploitRemedyVendor |
| https://www.vulncheck.com/advisories/hkuds-nanobot-before-0.3.0-server-side-request-forgery-via-webfetchtool | [email protected] | Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| HKUDS nanobot | < 0.3.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 17, 2026 | CVE Modified | CISA-ADP |
| Sep 16, 2026 | New CVE Received | [email protected] |
Volerion