PT-2026-83291 · Unknown · Qwen-Agent

·

CVE-2026-82268

·

Published

2026-08-28

·

Updated

2026-08-28

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Qwen-Agent versions prior to 0.0.35
Description A server-side request forgery (SSRF) issue exists in the document parsing path. The system treats paths provided by the caller as URLs without validating the host or restricting the scheme. This allows unauthenticated users via the Gradio interface to force the server to send HTTP requests to arbitrary internal addresses, such as metadata services, and retrieve the content through the parsed document output.
Recommendations Update Qwen-Agent to version 0.0.35 or later.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82268

Affected Products

Qwen-Agent