CVE-2026-33654 details a high-severity indirect prompt injection vulnerability (CVSS 8.9) affecting nanobot personal AI assistant versions prior to 0.1.6, specifically in its email channel processing module. This flaw allows a remote, unauthenticated attacker to execute arbitrary LLM instructions and system tools. The attack is zero-click and stealthy, occurring when the bot automatically processes a malicious email sent to its monitored address, bypassing channel isolation. Currently, there is no evidence of active exploitation, public exploit code availability, or significant community discussion regarding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.1.4CPE matchmatch criteria | cpe:2.3:a:nanobot:nanobot:*:*:*:*:*:python:*:* | ||
0.1.4CPE matchmatch criteria | cpe:2.3:a:nanobot:nanobot:0.1.4:-:*:*:*:python:*:* | ||
0.1.4CPE matchmatch criteria | cpe:2.3:a:nanobot:nanobot:0.1.4:post1:*:*:*:python:*:* | ||
0.1.4CPE matchmatch criteria | cpe:2.3:a:nanobot:nanobot:0.1.4:post2:*:*:*:python:*:* | ||
0.1.4CPE matchmatch criteria | cpe:2.3:a:nanobot:nanobot:0.1.4:post3:*:*:*:python:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.