Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

HKUDS — Vulnerabilities & Security Advisories 34

Browse all 34 CVE security advisories affecting HKUDS. AI-powered Chinese analysis, POCs, and references for each vulnerability.

HKUDS is a software platform primarily used for enterprise content management and document processing workflows. Historically, it has been susceptible to multiple remote code execution vulnerabilities, cross-site scripting flaws, and privilege escalation issues, accounting for its 14 recorded CVEs. The platform's complex architecture and extensive integration capabilities have contributed to persistent security challenges, with several critical vulnerabilities allowing unauthorized system access and data exfiltration. While no major public security incidents have been widely documented, the consistent pattern of vulnerabilities in its web interface and API components remains a significant concern for organizations relying on this system for sensitive document handling.

Found 11 results / 34 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-19246 HKUDS nanobot Provider-returned Image URL image_generation.py _download_image_data_url server-side request forgery — nanobot CWE-918 6.3 Medium 2026-08-07
CVE-2026-19245 HKUDS nanobot Login-shell Environment shell.py ExecTool._prepare_command information disclosure — nanobot CWE-200 3.3 Low 2026-08-07
CVE-2026-19244 HKUDS nanobot MCP enabledTools Scope mcp.py connect_mcp_servers access control — nanobot CWE-284 4.7 Medium 2026-08-07
CVE-2026-19243 HKUDS nanobot Shell Allowlist shell.py ExecTool._spawn os command injection — nanobot CWE-78 6.3 Medium 2026-08-07
CVE-2026-48716 nanobot: Path traversal via unsanitized WhatsApp document fileName enables arbitrary file write — nanobot CWE-22 8.7 High 2026-06-18
CVE-2026-49140 Nanobot < 0.2.1 Denial of Service via Matrix Media Download Handler — nanobot CWE-770 4.3 Medium 2026-06-01
CVE-2026-49139 Nanobot < 0.2.1 SSRF via Microsoft Teams Channel serviceUrl Poisoning — nanobot CWE-918 7.0 High 2026-06-01
CVE-2026-49138 Nanobot < 0.2.1 SSRF via web_fetch Tool Redirect Following — nanobot CWE-918 5.0 Medium 2026-06-01
CVE-2026-35589 nanobot: Cross-Site WebSocket Hijacking in WhatsApp Bridge (CVE-2026-2577 Fix Update) — nanobot CWE-1385 8.0 High 2026-04-14
CVE-2026-33654 Zero-Click Indirect Prompt Injection and Authentication Bypass via Email Polling — nanobot CWE-94 10.0 - 2026-03-27
CVE-2026-2577 Nanobot Unauthenticated WhatsApp Session Hijack via WebSocket Bridge — nanobot CWE-306 10.0 Critical 2026-02-16

This page lists every published CVE security advisory associated with HKUDS. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.