CVE-2026-2577Disclosure

LOWCVSS 10.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The WhatsApp bridge component in Nanobot binds the WebSocket server to all network interfaces (0.0.0.0) on port 3001 by default and does not require authentication for incoming connections. An unauthenticated remote attacker with network access to the bridge can connect to the WebSocket server to hijack the WhatsApp session. This allows the attacker to send messages on behalf of the user, intercept all incoming messages and media in real-time, and capture authentication QR codes.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

DECLINING

Threat summary

  • Patch or workaround signal is available
  • 11 mentions across 5 observed days
  • Momentum state: declining

What's happening

  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 9 signals
  • Disclosure: 8 classified signals
  • General: 2 classified signals
  • Peaked 4d ago at 6 mentions (2026-02-16); latest day: 1
  • 11 total mentions across 5 days

Deep dive

Activity timeline11 mentions / 5d
02356Mentions · 2026-02-16: 6Mentions · 2026-02-17: 2Mentions · 2026-02-20: 1Mentions · 2026-02-24: 1Mentions · 2026-04-23: 1Patch / Workaround · 2026-02-16: 2Patch / Workaround · 2026-02-17: 2Patch / Workaround · 2026-04-23: 1Technical Details · 2026-02-16: 6Technical Details · 2026-02-17: 1Technical Details · 2026-02-20: 1Technical Details · 2026-04-23: 102-1602-1702-2002-2404-23
Signal classification3 categories
Disclosure
872.7%
General
218.2%
Patch
19.1%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-02-166
Disclosure5General1
2026-02-172
Disclosure1Patch1
2026-02-201
Disclosure1
2026-02-241
General1
2026-04-231
Disclosure1
Full discourse11 posts
  • CCB Alert@CCBalert
    Disclosure

    Warning: Critical Vulnerability in #Nanobot. CVE-2026-2577 CVSS: 10. The WhatsApp bridge accepts incoming connections from all network interfaces and does no authentication. An attacker can hijack user’s #WhatsApp sessions, sending and receiving all messages. #Patch #Patch #Patch

    Post summary

    A critical vulnerability (CVE-2026-2577) in Nanobot’s WhatsApp bridge allows unauthenticated remote attackers to hijack WhatsApp sessions; a patch is urged.

    00012300
    7.2K followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Patch

    Infostealer malware, likely a Vidar variant, has been found stealing OpenClaw config and memory files with API keys and tokens, risking full AI agent identity compromise. Nanobot remote flaw CVE-2026-2577 patched. #OpenClaw #VidarMalware #NanobotFlaw https://ift.tt/pw0ONeA

    Post summary

    The post indicates that the Nanobot remote flaw CVE-2026-2577 has been patched, while also reporting a Vidar‑variant infostealer that stole OpenClaw credentials.

    10020146
    3.6K followersView on X
  • SuperMarioBros.🌍🇪🇺🇩🇪🇺🇦🇮🇱@Ma_Rio_Ho
    General

    @m_t_mask CVE-2026-2577 Score 10/10 Ist ja nicht so das davor gewarnt wurde. https://www.bleepingcomputer.com/news/security/infostealer-malware-found-stealing-openclaw-secrets-for-first-time/amp/

    Post summary

    The tweet references CVE-2026-2577 with a 10/10 score and links to a news article about infostealer malware, but offers no technical details, exploit code, or mitigation information.

    00020122
    1.9K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-2577 The WhatsApp bridge component in Nanobot binds the WebSocket server to all network interfaces (0.0.0.0) on port 3001 by default and does not require authentication for … https://www.cve.org/CVERecord?id=CVE-2026-2577

    Post summary

    The CVE-2026-2577 disclosure notes that the Nanobot WhatsApp bridge binds its WebSocket server to all interfaces (0.0.0.0) on port 3001 by default without requiring authentication, exposing a potential remote access vector. No PoC, exploit, patch, or active exploitation is mentioned.

    00010335
    56.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-2577 WhatsApp Session Hijacking Vulnerability in Nanobot WebSocket Bridge https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-2577

    Post summary

    The text announces CVE‑2026‑2577 as a WhatsApp session hijacking flaw in Nanobot WebSocket Bridge, but offers no exploitation details, patch information, or evidence of active attacks.

    0001050
    4.0K followersView on X
  • Giuseppe Paternicola@giuseppe_1337
    Disclosure

    nanobot is a personal AI assistant. Versions prior to 0.1.5 contain a Cross-Site WebSocket Hijacking (CSWSH) vulnerability exists in the bridge's WebSocket server in bridge/src/server.ts, resulting from an incomplete remediation of CVE-2026-2577. The original fix changed the binding from 0.0.0.0 to 127.0.0.1 and added an optional BRIDGE_TOKEN parameter, but token authentication is disabled by default and the server does not validate the Origin header during the WebSocket handshake. Because browsers do not enforce the Same-Origin Policy on WebSockets unless the server explicitly denies cross-origin connections, any website visited by a user running the bridge can establish a WebSocket connection to ws://127.0.0.1:3001/ and gain full access to the bridge API. This allows an attacker to hijack the WhatsApp session, read incoming messages, steal authentication QR codes, and send messages on behalf of the user. This issue has bee fixed in version 0.1.5.

    Post summary

    The excerpt describes a Cross‑Site WebSocket Hijacking flaw in nanobot’s earlier releases, detailing the vulnerability mechanics and noting it was fixed in the 0.1.5 update.

    0000046
    26 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-2577 (CVSS:10.0, CRITICAL) is Awaiting Analysis. The WhatsApp bridge component in Nanobot binds the WebSocket server to all network interfaces (0.0.0.0) on port 3001 by ..https://nvd.nist.gov/vuln/detail/CVE-2026-2577 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2026-2577, providing its critical CVSS score and a brief technical detail of how the vulnerability arises, but offers no PoC, exploit code, or patch information.

    0000041
    171 followersView on X
  • Säkerhetsbloggen@Sakerhetsblogg
    Disclosure

    CVE-2026-2577 tillåter obehöriga att utnyttja en osäker WebSocket-server i Nanobot. Angripare kan skicka meddelanden på användarens vägnar och avlyssna trafik i realtid! Prioritera uppdateringarna. #säkerhet #cybersäkerhet #CVE

    Post summary

    CVE-2026-2577 reveals an insecure WebSocket in Nanobot that permits attackers to send messages on behalf of users and eavesdrop traffic; users are urged to prioritize updates.

    0000042
    7 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-2577 - Critical The WhatsApp bridge component in Nanobot binds the WebSocket server to all network interfaces (0.0.0.0) on port 3001 by default and does not require authentication for incoming connections... https://www.thehackerwire.com/vulnerability/CVE-2026-2577/ https://t.co/L5ubMuyLqt

    Post summary

    The post reports on a critical CVE‑2026‑2577 affecting Nanobot’s WhatsApp bridge, noting that its WebSocket server is bound to all interfaces (0.0.0.0) on port 3001 without requiring authentication, potentially enabling unauthenticated access.

    0000059
    112 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-2577: CRITICAL] ⚠️Critical alert: Nanobot's WhatsApp bridge has a serious security flaw allowing remote attackers to hijack sessions, intercept messages, and capture QR codes without authentication. ...#cve,CVE-2026-2577,#cybersecurity https://cvefind.com/CVE-2026-2577

    Post summary

    The post announces a critical vulnerability (CVE-2026-2577) in Nanobot's WhatsApp bridge that permits remote session hijacking, message interception, and QR code capture without authentication.

    0000063
    580 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Disclosure

    🚨 CVE-2026-2577: CRITICAL flaw in HKUDS nanobot WhatsApp bridge! Unauthenticated access on port 3001 lets attackers hijack sessions & read/send messages. Restrict access & monitor now. https://radar.offseq.com/threat/cve-2026-2577-cwe-306-missing-authentication-for-c-d0d526e7 ... https://t.co/wdYgjiKEVu

    Post summary

    A critical unauthenticated access flaw in the HKUDS nanobot WhatsApp bridge (CVE‑2026‑2577) permits attackers to hijack sessions on port 3001; users are advised to restrict access and monitor activity.

    0000031
    265 followersView on X

Explore more