HKUDS has 4 CVEs on record. 4 were published in the last 90 days. The busiest recent month was September 2026 with 4. The median CVSS is 7.9 (high), with 1 rated critical. Most affected products: nanobot (3), AutoAgent (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.9
- Publish → KEV
- —
- Last 90 days
- 4 prev 0
Worst active — by depth score
CVE-2026-92576High· 8.6HKUDS nanobot before 0.3.0 contains a server-side request forgery vulnerability in the WebFetchTool component where the _validate_url() function fails to block internal IP ranges and private addresses59CVE-2026-86124Critical· 9.8AutoAgent contains an unauthenticated remote code execution vulnerability in the TCP server that binds to all interfaces and executes attacker-supplied commands as root54CVE-2026-90808Medium· 6.3A vulnerability was determined in HKUDS nanobot up to 0.2.147CVE-2026-90809High· 7.3A vulnerability was identified in HKUDS nanobot up to 0.2.140
HKUDS vulnerabilities
CVEs affecting HKUDS, newest first. Open any entry for full detail, references, and exploit status.
4 CVEsRSS
CVE-2026-92576High· 8.6PoCHKUDS nanobot before 0.3.0 contains a server-side request forgery vulnerability in the WebFetchTool component where the _validate_url() function fails to block internal IP ranges and private addresses
HKUDS nanobot before 0.3.0 contains a server-side request forgery vulnerability in the WebFetchTool component where the _validate_url() function fails to block internal IP ranges and private addresses. Attackers can send messages instruc…
CVE-2026-90808Medium· 6.3PoCA vulnerability was determined in HKUDS nanobot up to 0.2.1
A vulnerability was determined in HKUDS nanobot up to 0.2.1. Impacted is the function ExecTool._guard_command/ExecTool._spawn of the file nanobot/agent/tools/shell.py of the component ExecTool. This manipulation causes incomplete blackli…
CVE-2026-90809High· 7.3A vulnerability was identified in HKUDS nanobot up to 0.2.1
A vulnerability was identified in HKUDS nanobot up to 0.2.1. The affected element is the function ExecTool._guard_command/ExecTool._spawn of the file nanobot/agent/tools/shell.py of the component ExecTool. Such manipulation leads to argu…
CVE-2026-86124Critical· 9.8AutoAgent contains an unauthenticated remote code execution vulnerability in the TCP server that binds to all interfaces and executes attacker-supplied commands as root
AutoAgent contains an unauthenticated remote code execution vulnerability in the TCP server that binds to all interfaces and executes attacker-supplied commands as root. Attackers can connect to the exposed communication port and execute…