<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:hkuds:nanobot:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3ahkudsnanobot/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 14 Sep 2026 19:36:08 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3ahkudsnanobot/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Remote Argument Injection in HKUDS nanobot</title><link>https://feed.craftedsignal.io/briefs/2026-09-hku-nanobot-argument-injection/</link><pubDate>Mon, 14 Sep 2026 19:36:08 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-hku-nanobot-argument-injection/</guid><description>HKUDS nanobot versions up to 0.2.1 contain an argument injection vulnerability in the ExecTool component that allows remote attackers to execute arbitrary commands.</description><content:encoded><![CDATA[<p>HKUDS nanobot versions up to 0.2.1 are vulnerable to remote argument injection within the ExecTool component. The flaw exists in the <code>ExecTool._guard_command</code> and <code>ExecTool._spawn</code> functions located in <code>nanobot/agent/tools/shell.py</code>. An attacker can manipulate arguments passed to these functions, leading to command injection on the host system. This vulnerability allows for remote execution, significantly impacting the confidentiality, integrity, and availability of the affected environment. Organizations utilizing versions 0.2.1 and earlier should apply patch <code>af582246f141311d574551b7571a517bcc3df750</code> immediately to mitigate potential exploitation.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-90809 enables unauthenticated remote code execution, granting attackers the ability to execute arbitrary commands within the context of the nanobot agent. This could result in unauthorized system access, data exfiltration, or complete system compromise, depending on the privileges of the service account running the agent.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade HKUDS nanobot to a version containing the fix for CVE-2026-90809 by applying patch <code>af582246f141311d574551b7571a517bcc3df750</code>.</li>
<li>Restrict access to the nanobot agent management interface to authorized networks and IP addresses.</li>
<li>Review and audit the configuration of the <code>ExecTool</code> component to ensure command arguments are properly sanitized before processing.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>rce</category><category>command-injection</category><category>ssrf</category><category>cloud-security</category></item></channel></rss>