CVE 5.3 MEDIUM

Nanobot < 0.2.1 SSRF via web_fetch Tool Redirect Following_CVE-2026-49138

5.3 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:L/SI:N/SA:N

Description

Nanobot prior to version 0.2.1 contains a server-side request forgery vulnerability in the web_fetch tool that allows remote attackers to reach internal or private network hosts by supplying a URL that redirects to a loopback or private address via a 3xx Location header. Attackers can exploit the automatic HTTP redirect following behavior in the httpx library to bypass initial URL validation and cause the runtime to send outbound requests to internal hosts before final resolved URL validation is applied.

Basic Information

ID CVE-2026-49138
Source VulnCheck
Published Jun 1, 2026 at 19:41
Modified Jun 1, 2026 at 19:51

Affected Product

Vendor HKUDS
Product nanobot
Affected Versions HKUDS nanobot 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.