Qwen-Agent Server-Side Request Forgery via Caller-Supplied Document URL
21Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 8.7epss 0.4%
probabilidade de exploração
0.4%top 74% das CVEs
exploração observada
nãonenhuma fonte reporta
Qwen-Agent through 0.0.34 contains a server-side request forgery vulnerability in the document parsing path that treats caller-supplied paths as URLs without scheme restriction or host validation. Attackers can reach the unauthenticated Gradio interface to make the server issue HTTP requests to arbitrary internal addresses including metadata services and read retrieved content through parsed document output.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Produtos afetados
QwenLM · Qwen-AgentReferências
https://github.com/QwenLM/Qwen-Agenthttps://github.com/QwenLM/Qwen-Agent/blob/31a4d36d123688581a9e9744427272b33ce940e0/qwen_agent/tools/simple_doc_parser.pyhttps://github.com/QwenLM/Qwen-Agent/issues/913https://www.vulncheck.com/advisories/qwen-agent-server-side-request-forgery-via-caller-supplied-document-url