CVE-2026-19246: HKUDS nanobot Provider-returned Image URL image_generation.py _download_image_data_url server-side request forgery
A vulnerability has been found in HKUDS nanobot up to 0.2.1. This affects the function downloadimagedataurl of the file nanobot/providers/imagegeneration.py of the component Provider-returned Image URL Handler. The manipulation leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of the patch is 5095. It is recommended to apply a patch to fix this issue. The vendor explains: "We confirm that provider-returned image URLs required the same SSRF protections applied to other network retrieval paths. (...) The patch is currently available on main and is planned for the next patch release, v0.3.1."
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
HKUDS nanobotto a version that resolves this vulnerability.Fixed in 0.3.1Patch 5095
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19246?
The severity of CVE-2026-19246 is rated as medium with a score of 6.3.
How do I fix CVE-2026-19246?
To fix CVE-2026-19246, update HKUDS nanobot to the latest version where the vulnerability is patched.
What type of vulnerability is CVE-2026-19246?
CVE-2026-19246 is classified as a server-side request forgery (SSRF) vulnerability.
What components are affected by CVE-2026-19246?
CVE-2026-19246 affects the _download_image_data_url function in the image_generation.py component of HKUDS nanobot.
What are the potential consequences of CVE-2026-19246?
Exploitation of CVE-2026-19246 could allow attackers to initiate unauthorized requests from the server, potentially compromising internal resources.