CVE-2026-19243 | HKUDS nanobot up to 0.2.1 Shell Allowlist shell.py ExecTool._guard_command/ExecTool._spawn os command injection (Issue 4521 / ID 4562)

SecurityVulns

A vulnerability categorized as critical has been discovered in HKUDS nanobot up to 0.2.1. Impacted is the function ExecTool._guard_command/ExecTool._spawn of the file nanobot/agent/tools/shell.py of the component Shell Allowlist Handler. Such manipulation leads to os command injection.

This vulnerability is documented as CVE-2026-19243. The attack can be executed remotely. Additionally, an exploit exists.

It is advisable to upgrade the affected component.

Multiple issues were reported to the project. They reacted with a high level of professionalism and kindness: “These five reports are variants of the same root cause: validation of shell commands containing multiple segments, wrappers, comments, or chained commands. The issue was fixed by validating every executable shell segment against the configured allowlist”.VulDB Recent EntriesRead More