GHSA-434r-7c99-hwf3

Suggest an improvement
Source
https://github.com/advisories/GHSA-434r-7c99-hwf3
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-434r-7c99-hwf3/GHSA-434r-7c99-hwf3.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-434r-7c99-hwf3
Aliases
Published
2026-06-01T21:30:44Z
Modified
2026-08-04T14:41:01Z
Severity
  • 5.0 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N CVSS Calculator
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:L/SI:N/SA:N CVSS Calculator
Summary
Nanobot contains a server-side request forgery vulnerability in the web_fetch tool
Details

Nanobot prior to version 0.2.1 contains a server-side request forgery vulnerability in the web_fetch tool that allows remote attackers to reach internal or private network hosts by supplying a URL that redirects to a loopback or private address via a 3xx Location header. Attackers can exploit the automatic HTTP redirect following behavior in the httpx library to bypass initial URL validation and cause the runtime to send outbound requests to internal hosts before final resolved URL validation is applied.

Database specific
{
    "cwe_ids":  [
        "CWE-918"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-07-27T16:02:26Z",
    "nvd_published_at":  "2026-06-01T21:16:46Z",
    "severity":  "MODERATE"
}
References

Affected packages

PyPI / nanobot-ai

Package

Name
nanobot-ai
View open source insights on deps.dev
Purl
pkg:pypi/nanobot-ai

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.2.1

Affected versions

0.*
0.1.3.post7
0.1.4
0.1.4.post2
0.1.4.post3
0.1.4.post4
0.1.4.post5
0.1.4.post6
0.1.5
0.1.5.post1
0.1.5.post2
0.1.5.post3
0.2.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-434r-7c99-hwf3/GHSA-434r-7c99-hwf3.json"