Zero-click prompt injection in nanobot AI assistant email channel (CVE-2026-33654)
An indirect prompt injection vulnerability in the email channel module of the nanobot personal AI assistant (prior to version 0.1.6) let a remote, unauthenticated attacker send an email to the bot's monitored address and have its contents processed as trusted input, executing arbitrary LLM instructions and system tools with no owner interaction. The issue was patched in version 0.1.6.
Disclosed 27 March 2026 · Record updated 13 September 2026
Impact
Remote unauthenticated attackers could trigger arbitrary LLM instructions and downstream system tool execution via a crafted email, bypassing channel isolation in a stealthy zero-click attack.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-33654
