CVE-2026-92576

CVE-2026-92576 published: HKUDS nanobot before 0.3.0 contains a server-side request forgery vulnerability in the WebFetchTool component where the _validate_url() function fails to block internal IP ranges and private addresses. Attackers can send messages instructing the bot to fetc...

View full NVD advisory → ← Back to CVE watch