1 character.
0 authentication.
Full Agent Loop access.
CVE-2026-31977: a `|` in the sender address bypasses nanobot's Channel allowlist entirely β exposing every tool, file, and network capability the agent has.
BitsLab disclosure inside β
It took one character to break it.
`|` β that's all an attacker needs to bypass nanobot's Channel allowlist and slip into the Agent Loop with full access to whatever tools the deployment exposes.
CVE-2026-31977. The first vuln BitsLab found in nanobot. Read on β