Answer in brief
CVE-2026-49138 records a Medium severity ssrf vulnerability in Nanobot contains a server-side request forgery vulnerability in the web_fetch tool. The source record does not mark it as known exploited. 1 affected package is mapped in the feed.
Answer in brief
CVE-2026-49138 records a Medium severity ssrf vulnerability in Nanobot contains a server-side request forgery vulnerability in the web_fetch tool. The source record does not mark it as known exploited. 1 affected package is mapped in the feed.
Update nanobot-ai to 0.2.1 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanSSRF describes the vulnerability class recorded for this advisory. The current record does not mark CVE-2026-49138 as known exploited; continue to monitor the source for status changes. The feed includes package mappings that can be checked against lockfiles and deployed manifests.
| Package | Affected range | Fixed version |
|---|---|---|
| nanobot-aipip | <0.2.1 | 0.2.1 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
CVE-2026-49138 records a Medium severity ssrf vulnerability in Nanobot contains a server-side request forgery vulnerability in the web_fetch tool. The source record does not mark it as known exploited. 1 affected package is mapped in the feed.
The source record does not mark it as known exploited.
Check lockfiles and deployed manifests for nanobot-ai.
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL GuardUpdate nanobot-ai to 0.2.1 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanSSRF describes the vulnerability class recorded for this advisory. The current record does not mark CVE-2026-49138 as known exploited; continue to monitor the source for status changes. The feed includes package mappings that can be checked against lockfiles and deployed manifests.
| Package | Affected range | Fixed version |
|---|---|---|
| nanobot-aipip | <0.2.1 | 0.2.1 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
CVE-2026-49138 records a Medium severity ssrf vulnerability in Nanobot contains a server-side request forgery vulnerability in the web_fetch tool. The source record does not mark it as known exploited. 1 affected package is mapped in the feed.
The source record does not mark it as known exploited.
Check lockfiles and deployed manifests for nanobot-ai.
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL GuardNanobot prior to version 0.2.1 contains a server-side request forgery vulnerability in the web_fetch tool that allows remote attackers to reach internal or private network hosts by supplying a URL that redirects to a loopback or private address via a 3xx Location header. Attackers can exploit the automatic HTTP redirect following behavior in the httpx library to bypass initial URL validation and cause the runtime to send outbound requests to internal hosts before final resolved URL validation is applied.
Nanobot prior to version 0.2.1 contains a server-side request forgery vulnerability in the web_fetch tool that allows remote attackers to reach internal or private network hosts by supplying a URL that redirects to a loopback or private address via a 3xx Location header. Attackers can exploit the automatic HTTP redirect following behavior in the httpx library to bypass initial URL validation and cause the runtime to send outbound requests to internal hosts before final resolved URL validation is applied.