云虫漏洞情报

CVE-2026-82268 - Qwen-Agent through 0.0.34 contains a server-side request forgery vulnerability in the document parsing path that treats caller-supplied paths as URLs without scheme restriction or host validation. Attackers can reach the unauthenticated Gradio interface to make the server issue HTTP requests to arbitrary internal addresses including metadata services and read retrieved content through parsed document output. - 漏洞详情

漏洞编号:CVE-2026-82268

风险等级:高危

漏洞来源:CVE

CVE 编号:CVE-2026-82268

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-918

发布/更新时间:2026-08-28 / 2026-08-28

漏洞描述

Qwen-Agent through 0.0.34 contains a server-side request forgery vulnerability in the document parsing path that treats caller-supplied paths as URLs without scheme restriction or host validation. Attackers can reach the unauthenticated Gradio interface to make the server issue HTTP requests to arbitrary internal addresses including metadata services and read retrieved content through parsed document output.

相关链接

相关漏洞

« 返回首页