VulnSea

HKUDS has 4 CVEs on record. 4 were published in the last 90 days. The busiest recent month was September 2026 with 4. The median CVSS is 7.9 (high), with 1 rated critical. Most affected products: nanobot (3), AutoAgent (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.9
Publish → KEV
Last 90 days
4 prev 0

Products

  • nanobot 3
  • AutoAgent 1
4
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

HKUDS vulnerabilities

CVEs affecting HKUDS, newest first. Open any entry for full detail, references, and exploit status.

4 CVEsRSS

CVE-2026-92576High· 8.6PoC
5d ago

HKUDS nanobot before 0.3.0 contains a server-side request forgery vulnerability in the WebFetchTool component where the _validate_url() function fails to block internal IP ranges and private addresses

HKUDS nanobot before 0.3.0 contains a server-side request forgery vulnerability in the WebFetchTool component where the _validate_url() function fails to block internal IP ranges and private addresses. Attackers can send messages instruc…

MidnightHKUDS · nanobotEPSS 0.40%via NVD
CVE-2026-90808Medium· 6.3PoC
1w ago

A vulnerability was determined in HKUDS nanobot up to 0.2.1

A vulnerability was determined in HKUDS nanobot up to 0.2.1. Impacted is the function ExecTool._guard_command/ExecTool._spawn of the file nanobot/agent/tools/shell.py of the component ExecTool. This manipulation causes incomplete blackli…

TwilightHKUDS · nanobotEPSS 0.29%via NVD
CVE-2026-90809High· 7.3
1w ago

A vulnerability was identified in HKUDS nanobot up to 0.2.1

A vulnerability was identified in HKUDS nanobot up to 0.2.1. The affected element is the function ExecTool._guard_command/ExecTool._spawn of the file nanobot/agent/tools/shell.py of the component ExecTool. Such manipulation leads to argu…

TwilightHKUDS · nanobotEPSS 0.33%via NVD
CVE-2026-86124Critical· 9.8
2w ago

AutoAgent contains an unauthenticated remote code execution vulnerability in the TCP server that binds to all interfaces and executes attacker-supplied commands as root

AutoAgent contains an unauthenticated remote code execution vulnerability in the TCP server that binds to all interfaces and executes attacker-supplied commands as root. Attackers can connect to the exposed communication port and execute…

MidnightHKUDS · AutoAgentEPSS 0.54%via NVD
HKUDS vulnerabilities (CVEs) · VulnSea