---
id: CVE-2026-92576
title: >-
  HKUDS nanobot before 0.3.0 contains a server-side request forgery
  vulnerability in the WebFetchTool component where the _validate_url() function
  fails to block internal IP ranges and private addresses
summary: >-
  HKUDS nanobot before 0.3.0 contains a server-side request forgery
  vulnerability in the WebFetchTool component where the _validate_url() function
  fails to block internal IP ranges and private addresses. Attackers can send
  messages instruc…
severity: high
cvss: 8.6
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'
cwe:
  - CWE-918
vendor: HKUDS
product: nanobot
affected:
  - nanobot < 0.3.0
published: '2026-09-16'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T14:17:54.510'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92576'
references:
  - url: 'https://github.com/HKUDS/nanobot/security/advisories/GHSA-vc5v-6vwm-wf9m'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/hkuds-nanobot-before-0.3.0-server-side-request-forgery-via-webfetchtool
    label: disclosure@vulncheck.com
  - url: 'https://github.com/HKUDS/nanobot/security/advisories/GHSA-vc5v-6vwm-wf9m'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-17T13:31:52.643978Z'
ingestedAt: '2026-09-16T22:06:50.936Z'
epss: 0.00401
epssPercentile: 0.34199
---

## Overview

HKUDS nanobot before 0.3.0 contains a server-side request forgery vulnerability in the WebFetchTool component where the _validate_url() function fails to block internal IP ranges and private addresses. Attackers can send messages instructing the bot to fetch cloud metadata endpoints, localhost services, and RFC 1918 addresses to extract IAM credentials and internal service data.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
