Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

HKUDS — Vulnerabilities & Security Advisories 34

Browse all 34 CVE security advisories affecting HKUDS. AI-powered Chinese analysis, POCs, and references for each vulnerability.

HKUDS is a software platform primarily used for enterprise content management and document processing workflows. Historically, it has been susceptible to multiple remote code execution vulnerabilities, cross-site scripting flaws, and privilege escalation issues, accounting for its 14 recorded CVEs. The platform's complex architecture and extensive integration capabilities have contributed to persistent security challenges, with several critical vulnerabilities allowing unauthorized system access and data exfiltration. While no major public security incidents have been widely documented, the consistent pattern of vulnerabilities in its web interface and API components remains a significant concern for organizations relying on this system for sensitive document handling.

Found 11 results / 34Clear Filters
CVE IDTitleCVSSSeverityPublished
CVE-2026-19246 HKUDS nanobot Provider-returned Image URL image_generation.py _download_image_data_url server-side request forgery — nanobotCWE-918 6.3 Medium2026-08-07
CVE-2026-19245 HKUDS nanobot Login-shell Environment shell.py ExecTool._prepare_command information disclosure — nanobotCWE-200 3.3 Low2026-08-07
CVE-2026-19244 HKUDS nanobot MCP enabledTools Scope mcp.py connect_mcp_servers access control — nanobotCWE-284 4.7 Medium2026-08-07
CVE-2026-19243 HKUDS nanobot Shell Allowlist shell.py ExecTool._spawn os command injection — nanobotCWE-78 6.3 Medium2026-08-07
CVE-2026-48716 nanobot: Path traversal via unsanitized WhatsApp document fileName enables arbitrary file write — nanobotCWE-22 8.7 High2026-06-18
CVE-2026-49140 Nanobot < 0.2.1 Denial of Service via Matrix Media Download Handler — nanobotCWE-770 4.3 Medium2026-06-01
CVE-2026-49139 Nanobot < 0.2.1 SSRF via Microsoft Teams Channel serviceUrl Poisoning — nanobotCWE-918 7.0 High2026-06-01
CVE-2026-49138 Nanobot < 0.2.1 SSRF via web_fetch Tool Redirect Following — nanobotCWE-918 5.0 Medium2026-06-01
CVE-2026-35589 nanobot: Cross-Site WebSocket Hijacking in WhatsApp Bridge (CVE-2026-2577 Fix Update) — nanobotCWE-1385 8.0 High2026-04-14
CVE-2026-33654 Zero-Click Indirect Prompt Injection and Authentication Bypass via Email Polling — nanobotCWE-94 10.0 -2026-03-27
CVE-2026-2577 Nanobot Unauthenticated WhatsApp Session Hijack via WebSocket Bridge — nanobotCWE-306 10.0 Critical2026-02-16

This page lists every published CVE security advisory associated with HKUDS. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.