AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-19246

MEDIUM · CVSS 6.3 EPSS 0.22% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-07 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

A vulnerability in the HKUDS nanobot up to version 0.2.1 allows for server-side request forgery (SSRF) through the _download_image_data_url function in the image generation component. This flaw can be exploited remotely, potentially leading to unauthorized access to internal resources. Organizations using affected versions should prioritize applying the available patch to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-19246
Severity
MEDIUM
CVSS
6.3
EPSS
0.22%

Original NVD Description

A vulnerability has been found in HKUDS nanobot up to 0.2.1. This affects the function _download_image_data_url of the file nanobot/providers/image_generation.py of the component Provider-returned Image URL Handler. The manipulation leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of the patch is 5095. It is recommended to apply a patch to fix this issue. The vendor explains: "We confirm that provider-returned image URLs required the same SSRF protections applied to other network retrieval paths. (...) The patch is currently available on main and is planned for the next patch release, v0.3.1."