CVE-2026-90809 | HKUDS nanobot up to 0.2.1 ExecTool shell.py ExecTool._guard_command/ExecTool._spawn argument injection

SecurityVulns

A vulnerability described as critical has been identified in HKUDS nanobot up to 0.2.1. The affected element is the function ExecTool._guard_command/ExecTool._spawn of the file nanobot/agent/tools/shell.py of the component ExecTool. Such manipulation leads to argument injection.

This vulnerability is referenced as CVE-2026-90809. It is possible to launch the attack remotely. No exploit is available.

It is best practice to apply a patch to resolve this issue.VulDB Recent EntriesRead More