CVE-2026-90808

Summary

A vulnerability was determined in HKUDS nanobot up to 0.2.1. Impacted is the function ExecTool._guard_command/ExecTool._spawn of the file nanobot/agent/tools/shell.py of the component ExecTool. This manipulation causes incomplete blacklist. It is possible to initiate the attack remotely. Patch name: af582246f141311d574551b7571a517bcc3df750. Applying a patch is the recommended action to fix this issue.

Affected Software

VendorProductVersion RangeStatus
HKUDSnanobot0.2.0affected
HKUDSnanobot0.2.1affected

Weaknesses

  • CWE-184: Incomplete Blacklist
  • CWE-183: Permissive List of Allowed Inputs

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: poc
    • Automatable: no
    • Technical Impact: partial

Additional References

References