CVE-2026-18973: falha de média gravidade em heshengtao super-agent-party
heshengtao super-agent-party extension_proxy Route server.py sanitize_proxy_url server-side request forgery
Publicada em
33Vexday Risk Score
Sem sinal de exploração. Ela tem prova de conceito pública.
ssvc Attendcvss 6.9epss 0.5%
probabilidade de exploração
0.5%top 58% das CVEs
exploração observada
nãonenhuma fonte reporta
1 exploit(s) público(s)
A vulnerability has been found in heshengtao super-agent-party up to 0.4.1. The impacted element is the function sanitize_proxy_url of the file server.py of the component extension_proxy Route. The manipulation of the argument url leads to server-side request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Produtos afetados
heshengtao · super-agent-partyPoCs públicas encontradas — 1
cve_referencegist.github.com/YLChen-007/2f12ffb785d975b46b73896c0fb8cb5dnão verificado⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.
CVEs relacionadas — heshengtao super-agent-party
No mesmo produto, das mais perigosas para as menos.
Referências
https://gist.github.com/YLChen-007/2f12ffb785d975b46b73896c0fb8cb5dhttps://vuldb.com/cve/CVE-2026-18973https://vuldb.com/submit/862456https://vuldb.com/submit/862458https://vuldb.com/submit/862570https://vuldb.com/submit/862608https://vuldb.com/vuln/386262https://vuldb.com/vuln/386262/cti