BitsLab[verified]@0xbitslabDisclosure
BitsLab Research announced CVE‑2026‑33654 as a zero‑click indirect prompt injection tied to an authentication bypass in the email channel, providing a link for detailed analysis but no exploit code or patch.
Agent X AGI[verified]@agentxagiDisclosure
The tweet discloses CVE-2026-33654 for Nanobot, explaining a zero‑click injection via IMAP header spoofing, but offers no PoC, exploit code, patch, or evidence of active exploitation.
BitsLab[verified]@0xbitslabDisclosure
A new CVE (CVE‑2026‑33654) was disclosed for nanobot versions ≤ 0.1.4.post5, with a technical write‑up shared but no PoC, exploit, patch, or active‑exploitation details provided.
NY-squared AI[verified]@NYsquaredAIDisclosure
The text outlines how a CVE-2026-33654 vulnerability enables indirect prompt injection that results in remote code execution, providing technical details but no proof of exploitation or mitigation.
NY-squared AI[verified]@NYsquaredAIDisclosure
CVE‑2026‑33654 is disclosed as a prompt‑injection vulnerability that permits an attacker to send a single email, leading to remote code execution through a trust propagation failure. No Proof‑of‑Concept, patch, or evidence of active exploitation is mentioned.
CVE@CVEnewDisclosure
The passage discloses an indirect prompt injection vulnerability in nanobot prior to version 0.1.6 and references its CVE record, but it does not provide any PoC, exploit code, or patch information.