Nanobot's vulnerability footprint is concentrated in a narrowly scoped product line and centers on application-layer weaknesses including authentication bypass through spoofing, code injection, template-engine injection, and improper WebSocket origin validation. These issues reflect common risks in web-application and communication-handling logic; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nanobot over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-33654CRITICAL nanobot is a personal AI assistant. Prior to version 0.1.6, an indirect prompt injection vulnerability exists in the email channel processing module (`nanobot/channels/email.py`), | Mar 27, 2026 | 9.8 | 33 | NO | NO |
CVE-2026-35589CRITICAL nanobot is a personal AI assistant. Versions prior to 0.1.5 contain a Cross-Site WebSocket Hijacking (CSWSH) vulnerability exists in the bridge's WebSocket server in bridge/src/ser | Apr 14, 2026 | 9.3 | 31 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nanobot.
Media articles that mention a CVE ID that affects a product developed by Nanobot — matched by CVE ID, not by vendor name.