CVE-2026-19246

Source
https://cve.org/CVERecord?id=CVE-2026-19246
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-19246.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-19246
Published
2026-08-07T21:00:14.107Z
Modified
2026-08-09T03:46:06.417274067Z
Severity
  • 2.1 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
HKUDS nanobot Provider-returned Image URL image_generation.py _download_image_data_url server-side request forgery
Details

A vulnerability has been found in HKUDS nanobot up to 0.2.1. This affects the function downloadimagedataurl of the file nanobot/providers/image_generation.py of the component Provider-returned Image URL Handler. The manipulation leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of the patch is 5095. It is recommended to apply a patch to fix this issue. The vendor explains: "We confirm that provider-returned image URLs required the same SSRF protections applied to other network retrieval paths. (...) The patch is currently available on main and is planned for the next patch release, v0.3.1."

Database specific
{
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-918"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/19xxx/CVE-2026-19246.json"
}
References

Affected packages

Git / github.com/hkuds/nanobot

Affected ranges

Type
GIT
Repo
https://github.com/hkuds/nanobot
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "0.2.0"
        },
        {
            "last_affected": "0.2.0"
        },
        {
            "introduced": "0.2.1"
        },
        {
            "last_affected": "0.2.1"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

0.*
0.2.0
0.2.1
v0.*
v0.2.0
v0.2.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-19246.json"