PT-2026-69149 · Nanobot · Nanobot
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
HKUDS nanobot versions prior to 0.3.1
Description
An issue exists in the Provider-returned Image URL Handler component within the
download image data url() function of the nanobot/providers/image generation.py file. This flaw allows a remote attacker to perform server-side request forgery (SSRF), a technique where the attacker induces the server to make requests to an unintended location. This occurs because provider-returned image URLs lacked the necessary protections applied to other network retrieval paths.Recommendations
Update to version 0.3.1 or apply patch 5095.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nanobot