Nanobot prior to version 0.2.1 contains a server-side request forgery vulnerability in the Microsoft Teams channel handler that allows remote attackers to exfiltrate Bot Framework bearer tokens by supplying a forged activity with an attacker-controlled serviceUrl value. Attackers can poison the stored conversation reference by sending a crafted inbound activity to the Teams webhook, causing subsequent bot replies to transmit token-bearing Authorization header requests to an attacker-controlled host.
Metrics
Affected Vendors & Products
References
History
Mon, 01 Jun 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hkuds
Hkuds nanobot |
|
| Vendors & Products |
Hkuds
Hkuds nanobot |
Mon, 01 Jun 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nanobot prior to version 0.2.1 contains a server-side request forgery vulnerability in the Microsoft Teams channel handler that allows remote attackers to exfiltrate Bot Framework bearer tokens by supplying a forged activity with an attacker-controlled serviceUrl value. Attackers can poison the stored conversation reference by sending a crafted inbound activity to the Teams webhook, causing subsequent bot replies to transmit token-bearing Authorization header requests to an attacker-controlled host. | |
| Title | Nanobot < 0.2.1 SSRF via Microsoft Teams Channel serviceUrl Poisoning | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-01T19:50:42.993Z
Reserved: 2026-05-27T17:40:12.738Z
Link: CVE-2026-49139
No data.
Status : Received
Published: 2026-06-01T21:16:46.913
Modified: 2026-06-01T21:16:46.913
Link: CVE-2026-49139
No data.
OpenCVE Enrichment
Updated: 2026-06-01T22:00:12Z