๐Ÿ” CVE Alert

CVE-2026-49139

UNKNOWN 0.0

Nanobot < 0.2.1 SSRF via Microsoft Teams Channel serviceUrl Poisoning

CVSS Score
0.0
EPSS Score
0.1%
EPSS Percentile
32th

Nanobot prior to version 0.2.1 contains a server-side request forgery vulnerability in the Microsoft Teams channel handler that allows remote attackers to exfiltrate Bot Framework bearer tokens by supplying a forged activity with an attacker-controlled serviceUrl value. Attackers can poison the stored conversation reference by sending a crafted inbound activity to the Teams webhook, causing subsequent bot replies to transmit token-bearing Authorization header requests to an attacker-controlled host.

CWE CWE-918
Vendor hkuds
Product nanobot
Published Jun 1, 2026
Last Updated Jun 2, 2026
Stay Ahead of the Next One

Get instant alerts for hkuds nanobot

Be the first to know when new unknown vulnerabilities affecting hkuds nanobot are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

HKUDS / nanobot
0 < 0.2.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/HKUDS/nanobot/releases/tag/v0.2.1 github.com: https://github.com/HKUDS/nanobot/pull/4047 github.com: https://github.com/HKUDS/nanobot/commit/232df45126bcf0f8fccd123d73714f202c8e8612 vulncheck.com: https://www.vulncheck.com/advisories/nanobot-ssrf-via-microsoft-teams-channel-serviceurl-poisoning

Credits

Chia Min Jun Lennon