๐Ÿ” CVE Alert

CVE-2026-19246

MEDIUM 6.3

HKUDS nanobot Provider-returned Image URL image_generation.py _download_image_data_url server-side request forgery

CVSS Score
6.3
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability has been found in HKUDS nanobot up to 0.2.1. This affects the function _download_image_data_url of the file nanobot/providers/image_generation.py of the component Provider-returned Image URL Handler. The manipulation leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of the patch is 5095. It is recommended to apply a patch to fix this issue. The vendor explains: "We confirm that provider-returned image URLs required the same SSRF protections applied to other network retrieval paths. (...) The patch is currently available on main and is planned for the next patch release, v0.3.1."

CWE CWE-918
Vendor hkuds
Product nanobot
Published Aug 7, 2026
Stay Ahead of the Next One

Get instant alerts for hkuds nanobot

Be the first to know when new medium vulnerabilities affecting hkuds nanobot are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

HKUDS / nanobot
0.2.0 0.2.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/387000 vuldb.com: https://vuldb.com/vuln/387000/cti vuldb.com: https://vuldb.com/cve/CVE-2026-19246 vuldb.com: https://vuldb.com/submit/865113 gist.github.com: https://gist.github.com/YLChen-007/44bc77ac259e461c6938cc6c286c4430 github.com: https://github.com/HKUDS/nanobot/pull/5095 github.com: https://github.com/HKUDS/nanobot/

Credits

๐Ÿ” Eric-c (VulDB User) VulDB CNA Team