Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-35589

34
FAUCET Score

CVE-2026-35589 is a Cross-Site WebSocket Hijacking (CSWSH) vulnerability affecting nanobot, a personal AI assistant, in versions prior to 0.1.5. The vulnerability exists in the WebSocket server component located in bridge/src/server.ts and stems from an incomplete remediation of a previous vulnerability. An attacker can exploit this flaw by having a user visit a malicious website while running the bridge service, allowing the website to establish an unauthorized WebSocket connection and gain full access to the bridge API. The vulnerability carries a CVSS score of 8.0 (HIGH) with a network attack vector, high complexity, and no privilege requirements. Exploitation requires user interaction (UI:R) but affects the confidentiality and integrity of the affected system. The root cause is the failure to validate the Origin header during WebSocket handshake and the default-disabled token authentication mechanism. Successful exploitation enables attackers to hijack WhatsApp sessions, intercept incoming messages, steal authentication QR codes, and send unauthorized messages on behalf of the compromised user. There is currently no evidence of active exploitation, with the vulnerability absent from the Known Exploited Vulnerabilities (KEV) catalog and inactive on vulnerability hot lists. The EPSS score of 0.00021 indicates minimal historical exploitation probability. The vulnerability has been remediated in version 0.1.5, and organizations running nanobot should prioritize updating to this patched version to mitigate the risk.

Impacted Technologies

VendorProductVersion(s)CPE
< 0.1.5CPE matchmatch criteria
cpe:2.3:a:nanobot:nanobot:*:*:*:*:*:python:*:*

CVSS Data

CVSS version used by this source: 3.1

8.0HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
1.6
Impact Score
5.8
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.16%
Probability of exploitation in next 30 days
EPSS Percentile
5.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0016 is in the 2nd percentile among its peer group of 836 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.

Remediation

Vendor Patches (1)

github_advisoryvendor investigatingvia nvd_reference
View patch

References

github.com / HKUDS/nanobot/releases/tag/v0.1.5
ProductRelease Notes
github.com / HKUDS/nanobot/security/advisories/GHSA-v5j3-4q66-58cf
ExploitVendor Advisory