Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 02 Jun 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 01 Jun 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hkuds
Hkuds nanobot |
|
| Vendors & Products |
Hkuds
Hkuds nanobot |
Mon, 01 Jun 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nanobot prior to version 0.2.1 contains a server-side request forgery vulnerability in the Microsoft Teams channel handler that allows remote attackers to exfiltrate Bot Framework bearer tokens by supplying a forged activity with an attacker-controlled serviceUrl value. Attackers can poison the stored conversation reference by sending a crafted inbound activity to the Teams webhook, causing subsequent bot replies to transmit token-bearing Authorization header requests to an attacker-controlled host. | |
| Title | Nanobot < 0.2.1 SSRF via Microsoft Teams Channel serviceUrl Poisoning | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-02T15:46:15.707Z
Reserved: 2026-05-27T17:40:12.738Z
Link: CVE-2026-49139
Updated: 2026-06-02T15:27:17.695Z
Status : Deferred
Published: 2026-06-01T21:16:46.913
Modified: 2026-06-02T14:43:49.920
Link: CVE-2026-49139
No data.
OpenCVE Enrichment
Updated: 2026-06-01T22:00:12Z