PT-2026-66496 · Git+1 · Swarms

·

CVE-2026-67346

·

Published

2026-07-30

·

Updated

2026-07-30

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Swarms versions prior to 6.8.1
Description A server-side request forgery issue exists in the is safe url() function. The function fails to validate hostnames through DNS resolution, which allows the blocklist to be bypassed. Attackers can provide user-controlled image or audio URLs that resolve to loopback, private, or metadata addresses to access internal services and exfiltrate credentials.
Recommendations Update Swarms to a version that includes commit 8b0fc9e.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67346

Affected Products

Swarms