AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-19245

LOW · CVSS 3.3 EPSS 0.12% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-07 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

A vulnerability exists in the ExecTool._prepare_command function of the HKUDS nanobot up to version 0.2.1, allowing local attackers to manipulate command execution and potentially disclose sensitive information. Users of the affected component should prioritize upgrading to version 0.3.0, which addresses this issue through patch 4525. Organizations utilizing this software should assess their risk and apply the update promptly to mitigate the threat.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-19245
Severity
LOW
CVSS
3.3
EPSS
0.12%

Original NVD Description

A flaw has been found in HKUDS nanobot up to 0.2.1. The impacted element is the function ExecTool._prepare_command of the file nanobot/agent/tools/shell.py of the component Login-shell Environment Handler. Executing a manipulation can lead to information disclosure. The attack requires local access. The exploit has been published and may be used. Upgrading to version 0.3.0 is sufficient to resolve this issue. This patch is called 4525. The affected component should be upgraded. Multiple issues were reported to the project. They reacted with a high level of professionalism and kindness: "The report concerns shell startup files reintroducing environment variables when command execution defaults to a login shell. The default was changed so exec does not use a login shell unless explicitly requested".