GHSA-434r-7c99-hwf3
MODERATECVE-2026-49138Nanobot prior to version 0.2.1 contains a server-side request forgery vulnerability in the webfetch tool that allows remote attackers to reach internal or private network hosts by supplying a URL that redirects to a loopback or private address via a 3xx Location header. Attackers can exploit the automatic HTTP redirect following behavior in the httpx library to bypass initial URL validation and ca
- Affected
- < 0.2.1
- Fixed in
- 0.2.1
- Weakness
- CWE-918
- Published
- 2026-06-01
- Source
- github