CVE-2026-92576

Source
https://cve.org/CVERecord?id=CVE-2026-92576
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92576.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-92576
Aliases
  • GHSA-vc5v-6vwm-wf9m
Published
2026-09-16T21:46:45Z
Modified
2026-09-18T03:48:42Z
Severity
  • 9.2 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N CVSS Calculator
Summary
HKUDS nanobot before 0.3.0 Server-Side Request Forgery via WebFetchTool
Details

HKUDS nanobot before 0.3.0 contains a server-side request forgery vulnerability in the WebFetchTool component where the _validate_url() function fails to block internal IP ranges and private addresses. Attackers can send messages instructing the bot to fetch cloud metadata endpoints, localhost services, and RFC 1918 addresses to extract IAM credentials and internal service data.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-918"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92576.json"
}
References

Affected packages

Git / github.com/hkuds/nanobot

Affected ranges

Type
GIT
Repo
https://github.com/hkuds/nanobot
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "0.3.0"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ]
}

Affected versions

v0.*
v0.1.3.post4
v0.1.3.post5
v0.1.3.post6
v0.1.4
v0.1.4.post1
v0.1.4.post2
v0.1.4.post3
v0.1.4.post4
v0.1.4.post6
v0.1.5
v0.1.5.post1
v0.1.5.post2
v0.1.5.post3
v0.2.0
v0.2.1
v0.2.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92576.json"