CVE-2026-49139
Received Received - Intake
Server-Side Request Forgery in Nanobot Prior to 0.2.1

Publication date: 2026-06-01

Last updated on: 2026-06-01

Assigner: VulnCheck

Description
Nanobot prior to version 0.2.1 contains a server-side request forgery vulnerability in the Microsoft Teams channel handler that allows remote attackers to exfiltrate Bot Framework bearer tokens by supplying a forged activity with an attacker-controlled serviceUrl value. Attackers can poison the stored conversation reference by sending a crafted inbound activity to the Teams webhook, causing subsequent bot replies to transmit token-bearing Authorization header requests to an attacker-controlled host.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-01
Last Modified
2026-06-01
Generated
2026-06-02
AI Q&A
2026-06-02
EPSS Evaluated
N/A
NVD
Affected Vendors & Products
Currently, no data is known.
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability exists in Nanobot versions prior to 0.2.1 and involves a server-side request forgery (SSRF) issue in the Microsoft Teams channel handler.

Remote attackers can exploit this by sending a forged activity containing an attacker-controlled serviceUrl value to the Teams webhook.

This allows attackers to poison the stored conversation reference, causing the bot to send subsequent replies with Authorization header requests that include Bot Framework bearer tokens to an attacker-controlled host.


How can this vulnerability impact me? :

The vulnerability can lead to unauthorized exfiltration of Bot Framework bearer tokens.

Attackers gaining these tokens could impersonate the bot or access sensitive communications, potentially leading to further attacks or data breaches.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart