Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 14 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was determined in HKUDS nanobot up to 0.2.1. Impacted is the function ExecTool._guard_command/ExecTool._spawn of the file nanobot/agent/tools/shell.py of the component ExecTool. This manipulation causes incomplete blacklist. It is possible to initiate the attack remotely. Patch name: af582246f141311d574551b7571a517bcc3df750. Applying a patch is the recommended action to fix this issue. | |
| Title | HKUDS nanobot ExecTool shell.py ExecTool._spawn incomplete blacklist | |
| First Time appeared |
Nanobot
Nanobot nanobot |
|
| Weaknesses | CWE-183 CWE-184 |
|
| CPEs | cpe:2.3:a:nanobot:nanobot:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Nanobot
Nanobot nanobot |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-14T19:13:22.152Z
Reserved: 2026-09-13T16:10:33.299Z
Link: CVE-2026-90808
Updated: 2026-09-14T19:13:13.452Z
Status : Deferred
Published: 2026-09-14T19:18:10.700
Modified: 2026-09-14T20:56:48.220
Link: CVE-2026-90808
No data.
OpenCVE Enrichment
No data.
