Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vwc9-2889-5p3f

Опубликовано: 14 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.3
CVSS3: 6.3

Описание

A vulnerability was determined in HKUDS nanobot up to 0.2.1. Impacted is the function ExecTool._guard_command/ExecTool._spawn of the file nanobot/agent/tools/shell.py of the component ExecTool. This manipulation causes incomplete blacklist. It is possible to initiate the attack remotely. Patch name: af582246f141311d574551b7571a517bcc3df750. Applying a patch is the recommended action to fix this issue.

A vulnerability was determined in HKUDS nanobot up to 0.2.1. Impacted is the function ExecTool._guard_command/ExecTool._spawn of the file nanobot/agent/tools/shell.py of the component ExecTool. This manipulation causes incomplete blacklist. It is possible to initiate the attack remotely. Patch name: af582246f141311d574551b7571a517bcc3df750. Applying a patch is the recommended action to fix this issue.

EPSS

Процентиль: 21%
0.00287
Низкий

5.3 Medium

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-183

Связанные уязвимости

CVSS3: 6.3
nvd
6 дней назад

A vulnerability was determined in HKUDS nanobot up to 0.2.1. Impacted is the function ExecTool._guard_command/ExecTool._spawn of the file nanobot/agent/tools/shell.py of the component ExecTool. This manipulation causes incomplete blacklist. It is possible to initiate the attack remotely. Patch name: af582246f141311d574551b7571a517bcc3df750. Applying a patch is the recommended action to fix this issue.

EPSS

Процентиль: 21%
0.00287
Низкий

5.3 Medium

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-183