Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Nanobot Unauthenticated WhatsApp Session Hijack via WebSocket Bridge
Vulnerability Description
The WhatsApp bridge component in Nanobot binds the WebSocket server to all network interfaces (0.0.0.0) on port 3001 by default and does not require authentication for incoming connections. An unauthenticated remote attacker with network access to the bridge can connect to the WebSocket server to hijack the WhatsApp session. This allows the attacker to send messages on behalf of the user, intercept all incoming messages and media in real-time, and capture authentication QR codes.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Vulnerability Type
关键功能的认证机制缺失
Vulnerability Title
nanobot 安全漏洞
Vulnerability Description
nanobot是✨Data Intelligence Lab@HKU✨开源的一个轻量个人AI助手。 Nanobot存在安全漏洞,该漏洞源于WhatsApp bridge组件默认将WebSocket服务器绑定到所有网络接口且无需身份验证,可能导致会话劫持和信息泄露。
CVSS Information
N/A
Vulnerability Type
N/A