PT-2026-83291 · Unknown · Qwen-Agent
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Qwen-Agent versions prior to 0.0.35
Description
A server-side request forgery (SSRF) issue exists in the document parsing path. The system treats paths provided by the caller as URLs without validating the host or restricting the scheme. This allows unauthenticated users via the Gradio interface to force the server to send HTTP requests to arbitrary internal addresses, such as metadata services, and retrieve the content through the parsed document output.
Recommendations
Update Qwen-Agent to version 0.0.35 or later.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Qwen-Agent