CVE Explorer
CVE-2026-35589
nanobot is a personal AI assistant. Versions prior to 0.1.5 contain a Cross-Site WebSocket Hijacking (CSWSH) vulnerability exists in the bridge's WebSocket server in bridge/src/server.ts, resulting from an incomplete remediation of CVE-2026-2577. The original fix changed the binding from 0.0.0.0 to 127.0.0.1 and added an optional BRIDGE_TOKEN parameter, but token authentication is disabled by default and the server does not validate the Origin header during the WebSocket handshake. Because brows
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"nanobot","vendor":"HKUDS","versions":[{"status":"affected","version":"< 0.1.5"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:4119c9bfd11cd1fc9f4294c6f95666b1118fb409ace6698c96f92ab89c9d942f · sha256:ac9cb47e8c46a1fd… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:4119c9bfd11cd1fc9f4294c6f95666b1118fb409ace6698c96f92ab89c9d942f · sha256:ac9cb47e8c46a1fd… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-1385","description":"CWE-1385: Missing Origin Validation in WebSockets","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:4119c9bfd11cd1fc9f4294c6f95666b1118fb409ace6698c96f92ab89c9d942f · sha256:ac9cb47e8c46a1fd… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"name":"https://github.com/HKUDS/nanobot/releases/tag/v0.1.5","tags":["x_refsource_MISC"],"url":"https://github.com/HKUDS/nanobot/releases/tag/v0.1.5"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:4119c9bfd11cd1fc9f4294c6f95666b1118fb409ace6698c96f92ab89c9d942f · sha256:ac9cb47e8c46a1fd… · /containers/cna/references/1
{"name":"https://github.com/HKUDS/nanobot/security/advisories/GHSA-v5j3-4q66-58cf","tags":["x_refsource_CONFIRM"],"url":"https://github.com/HKUDS/nanobot/security/advisories/GHSA-v5j3-4q66-58cf"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:4119c9bfd11cd1fc9f4294c6f95666b1118fb409ace6698c96f92ab89c9d942f · sha256:ac9cb47e8c46a1fd… · /containers/cna/references/0
{"tags":["exploit"],"url":"https://github.com/HKUDS/nanobot/security/advisories/GHSA-v5j3-4q66-58cf"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:4119c9bfd11cd1fc9f4294c6f95666b1118fb409ace6698c96f92ab89c9d942f · sha256:ac9cb47e8c46a1fd… · /containers/adp/0/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.