CVE-2026-49138

Source
https://cve.org/CVERecord?id=CVE-2026-49138
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-49138.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-49138
Aliases
Published
2026-06-01T19:41:51.141Z
Modified
2026-07-28T03:55:42.986743307Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:L/SI:N/SA:N CVSS Calculator
Summary
Nanobot < 0.2.1 SSRF via web_fetch Tool Redirect Following
Details

Nanobot prior to version 0.2.1 contains a server-side request forgery vulnerability in the web_fetch tool that allows remote attackers to reach internal or private network hosts by supplying a URL that redirects to a loopback or private address via a 3xx Location header. Attackers can exploit the automatic HTTP redirect following behavior in the httpx library to bypass initial URL validation and cause the runtime to send outbound requests to internal hosts before final resolved URL validation is applied.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/49xxx/CVE-2026-49138.json",
    "cwe_ids": [
        "CWE-918"
    ],
    "cna_assigner": "VulnCheck"
}
References

Affected packages

Git / github.com/hkuds/nanobot

Affected ranges

Type
GIT
Repo
https://github.com/hkuds/nanobot
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
{
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "0.2.1"
        }
    ]
}

Affected versions

v0.*
v0.1.3.post4
v0.1.3.post5
v0.1.3.post6
v0.1.4
v0.1.4.post1
v0.1.4.post2
v0.1.4.post3
v0.1.4.post4
v0.1.4.post6
v0.1.5
v0.1.5.post1
v0.1.5.post2
v0.1.5.post3
v0.2.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-49138.json"