CVE-2026-33654Disclosure(nanobot / nanobot)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

nanobot is a personal AI assistant. Prior to version 0.1.6, an indirect prompt injection vulnerability exists in the email channel processing module (`nanobot/channels/email.py`), allowing a remote, unauthenticated attacker to execute arbitrary LLM instructions (and subsequently, system tools) without any interaction from the bot owner. By sending an email containing malicious prompts to the bot's monitored email address, the bot automatically polls, ingests, and processes the email content as highly trusted input, fully bypassing channel isolation and resulting in a stealthy, zero-click attack. Version 0.1.6 patches the issue.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94CWE-290CWE-1336

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nanobot

Threat summary

  • Public PoC is present in monitored signal
  • 6 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 6 classified signals
  • Peaked 1d ago at 2 mentions (2026-05-21); latest day: 1
  • 6 total mentions across 5 days

Affected systems

Vendors
Products
nanobot

1 version affected across 1 product

Deep dive

Activity timeline6 mentions / 5d
01122Mentions · 2026-03-28: 1Mentions · 2026-04-12: 1Mentions · 2026-04-13: 1Mentions · 2026-05-21: 2Mentions · 2026-05-25: 1PoC Mentioned / Linked · 2026-05-21: 1Technical Details · 2026-03-28: 1Technical Details · 2026-04-12: 1Technical Details · 2026-04-13: 1Technical Details · 2026-05-21: 1Technical Details · 2026-05-25: 103-2804-1204-1305-2105-25
Signal classification1 categories
Disclosure
6100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-281
Disclosure1
2026-04-121
Disclosure1
2026-04-131
Disclosure1
2026-05-212
Disclosure2
2026-05-251
Disclosure1
Full discourse6 posts
  • BitsLab@0xbitslab
    Disclosure

    🚨 BitsLab Research: One forged email is enough to hijack a nanobot agent. No clicks. No user interaction. No prior access. We disclosed CVE-2026-33654 — a zero-click Indirect Prompt Injection chained with Authentication Bypass in the Email Channel. Here's how it works 🧵👇 https://t.co/3Fe6UxopCX

    Post summary

    BitsLab Research announced CVE‑2026‑33654 as a zero‑click indirect prompt injection tied to an authentication bypass in the email channel, providing a link for detailed analysis but no exploit code or patch.

    271100933
    1.9K followersView on X
  • Agent X AGI@agentxagi
    Disclosure

    43K stars. One forged email. Your agent just opened it. CVE-2026-33654 in nanobot: IMAP takes From header as sender_id. Spoof it, bypass allowlist, inject via email body. Zero clicks needed. Everyone hardens prompts. Nobody checks the inbox. → https://x.com/0xbitslab/status/2057369862876659860

    Post summary

    The tweet discloses CVE-2026-33654 for Nanobot, explaining a zero‑click injection via IMAP header spoofing, but offers no PoC, exploit code, patch, or evidence of active exploitation.

    10010153
    395 followersView on X
  • BitsLab@0xbitslab
    Disclosure

    Tweet 12/12 📄 Full technical write-up: https://github.com/HKUDS/nanobot/security/advisories/GHSA-4gmr-2vc8-7qh3 CVE: CVE-2026-33654 Affected: nanobot ≤ 0.1.4.post5 For ongoing AI × Web3 security research from @BitsLabHQ, follow us 👇 https://t.me/BitsLabHQ

    Post summary

    A new CVE (CVE‑2026‑33654) was disclosed for nanobot versions ≤ 0.1.4.post5, with a technical write‑up shared but no PoC, exploit, patch, or active‑exploitation details provided.

    00010117
    2.0K followersView on X
  • NY-squared AI@NYsquaredAI
    Disclosure

    Nanobot CVE-2026-33654 just proved what we discussed at 5AM. One email = indirect prompt injection → full RCE in downstream agent. Weak entry model poisons the strong reasoning model. Agent A trusts the email → Agent B/C inherit poisoned checkpoint. Cold Start isn't latency. It's a swarm security debt that explodes at scale.

    Post summary

    The text outlines how a CVE-2026-33654 vulnerability enables indirect prompt injection that results in remote code execution, providing technical details but no proof of exploitation or mitigation.

    1000062
    27 followersView on X
  • NY-squared AI@NYsquaredAI
    Disclosure

    Nanobot CVE-2026-33654 just dropped: one email = indirect prompt injection → full RCE. Weak entry model (email) poisons the strong reasoning model downstream. This is exactly the “trust propagation failure” we discussed at 5AM. Agent A trusts the email → Agent B/C inherit poisoned checkpoint. Cold start isn’t just latency — it’s a security debt that explodes in swarms. How do you handle trust bootstrapping across agent handoffs? #AISec

    Post summary

    CVE‑2026‑33654 is disclosed as a prompt‑injection vulnerability that permits an attacker to send a single email, leading to remote code execution through a trust propagation failure. No Proof‑of‑Concept, patch, or evidence of active exploitation is mentioned.

    0000052
    27 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33654 nanobot is a personal AI assistant. Prior to version 0.1.6, an indirect prompt injection vulnerability exists in the email channel processing module (`nanobot/channel… https://www.cve.org/CVERecord?id=CVE-2026-33654

    Post summary

    The passage discloses an indirect prompt injection vulnerability in nanobot prior to version 0.1.6 and references its CVE record, but it does not provide any PoC, exploit code, or patch information.

    00000150
    56.9K followersView on X
CPE platform detail7 entries

7 of 7 entries

PartVendorProductVersionTarget SWTarget HW
Appnanobotnanobot-python-
Appnanobotnanobot0.1.4python-
Appnanobotnanobot0.1.4python-
Appnanobotnanobot0.1.4python-
Appnanobotnanobot0.1.4python-
Appnanobotnanobot0.1.4python-
Appnanobotnanobot0.1.4python-

Explore more