What is CVE-2026-19246?
CVE-2026-19246 is a Server-Side Request Forgery (SSRF) vulnerability in the `_download_image_data_url` function of HKUDS nanobot up to version 0.2.1. It allows remote exploitation through manipulation of provider-returned image URLs, potentially leading to unauthorized internal requests. Users should update nanobot to the latest version immediately.
Azərbaycanca: CVE-2026-19246, HKUDS proqramının 0.2.1-ə qədər olan versiyalarında `_download_image_data_url` funksiyası vasitəsilə Server-Side Request Forgery (SSRF) zəifliyidir. Bu, təchizatçıdan qaytarılan şəkil URL-lərinin manipulyasiyası ilə uzaqdan istismara imkan yaradır. İstifadəçilərə dərhal nanobot-u ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
Which versions of HKUDS are affected by CVE-2026-19246?
CVE-2026-19246 affects HKUDS nanobot up to version 0.2.1.
What should users do to mitigate CVE-2026-19246?
Users should update nanobot to the latest version immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.