CVE-2026-90808
Received Received - Intake

Incomplete Command Blacklist in HKUDS Nanobot

Vulnerability report for CVE-2026-90808, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-14

Assigner: VulDB

Description

A vulnerability was determined in HKUDS nanobot up to 0.2.1. Impacted is the function ExecTool._guard_command/ExecTool._spawn of the file nanobot/agent/tools/shell.py of the component ExecTool. This manipulation causes incomplete blacklist. It is possible to initiate the attack remotely. Patch name: af582246f141311d574551b7571a517bcc3df750. Applying a patch is the recommended action to fix this issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-14
Generated
2026-09-14
AI Q&A
2026-09-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
hkuds nanobot to 0.2.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-184 The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are not allowed by policy or otherwise require other action to neutralize before additional processing takes place, but the list is incomplete.
CWE-183 The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are explicitly allowed by policy because the inputs are assumed to be safe, but the list is too permissive - that is, it allows an input that is unsafe, leading to resultant weaknesses.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability exists in HKUDS nanobot up to version 0.2.1, specifically in the ExecTool._guard_command and ExecTool._spawn functions of the shell.py file. The issue allows incomplete blacklist validation, potentially enabling remote attackers to execute unauthorized commands.

Impact Analysis

An attacker could remotely exploit this flaw to bypass security controls and execute arbitrary commands on the affected system. This may lead to unauthorized access, data theft, or system compromise depending on the privileges of the nanobot service.

Mitigation Strategies

Apply the provided patch af582246f141311d574551b7571a517bcc3df750 to the nanobot component. Update HKUDS nanobot to version 0.2.1 or later if available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-90808. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart