CVE-2026-49138

MEDIUM

Nanobot < 0.2.1 - Server-Side Request Forgery via Web Fetch Tool Redirect Following

Title source: llm
STIX 2.1

Description

Nanobot prior to version 0.2.1 contains a server-side request forgery vulnerability in the web_fetch tool that allows remote attackers to reach internal or private network hosts by supplying a URL that redirects to a loopback or private address via a 3xx Location header. Attackers can exploit the automatic HTTP redirect following behavior in the httpx library to bypass initial URL validation and cause the runtime to send outbound requests to internal hosts before final resolved URL validation is applied.

Scores

CVSS v3 5.0
EPSS 0.0004
EPSS Percentile 13.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-918
Status published
Products (1)
HKUDS/nanobot < 0.2.1
Published Jun 01, 2026
Tracked Since Jun 02, 2026