MCPA-2026-0021
mediumssrfCVSS 5
HKUDS nanobot SSRF in the web_fetch tool via 3xx redirects (CVE-2026-49138)
HKUDS nanobot (PyPI: nanobot-ai) before 0.2.1 contains a server-side request forgery vulnerability in the web_fetch tool: a URL that passes initial validation can 3xx-redirect to a loopback or private-network address, and httpx's automatic redirect following fetches it, letting remote attackers reach internal hosts (e.g. cloud metadata endpoints) through the agent. Fixed in 0.2.1 (patch PR #3928).
Affected packages
| Ecosystem | Package | Affected versions |
|---|---|---|
| pypi | nanobot-ai | >= 0, < 0.2.1 |
Identifiers
CVE-2026-49138GHSA-434r-7c99-hwf3PYSEC-2026-3580CWE-918
References
- advisory https://github.com/advisories/GHSA-434r-7c99-hwf3
- web https://nvd.nist.gov/vuln/detail/CVE-2026-49138
- fix https://github.com/HKUDS/nanobot/pull/3928
- web https://github.com/HKUDS/nanobot/releases/tag/v0.2.1
Timeline
- Published: 2026-06-01