PT-2026-91404 · Hkuds · Nanobot
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
HKUDS nanobot versions prior to 0.2.2
Description
An argument injection flaw exists in the
ExecTool component, specifically within the ExecTool. guard command() and ExecTool. spawn() functions located in the nanobot/agent/tools/shell.py file. This issue allows a remote attacker to inject arguments into commands executed by the system.Recommendations
Apply patch af582246f141311d574551b7571a517bcc3df750 to resolve the issue.
As a temporary mitigation, restrict the use of the
ExecTool. guard command() and ExecTool. spawn() functions.Exploit
Fix
Argument Injection
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nanobot