CVE-2026-19245 | HKUDS nanobot up to 0.2.1 Login-shell Environment shell.py ExecTool._prepare_command information disclosure (Issue 4518 / ID 4525)

SecurityVulns

A vulnerability labeled as problematic has been found in HKUDS nanobot up to 0.2.1. The impacted element is the function ExecTool._prepare_command of the file nanobot/agent/tools/shell.py of the component Login-shell Environment Handler. Executing a manipulation can lead to information disclosure.

This vulnerability appears as CVE-2026-19245. The attack requires local access. In addition, an exploit is available.

The affected component should be upgraded.

Multiple issues were reported to the project. They reacted with a high level of professionalism and kindness: “The report concerns shell startup files reintroducing environment variables when command execution defaults to a login shell. The default was changed so exec does not use a login shell unless explicitly requested”.VulDB Recent EntriesRead More