{"data":{"id":"6068d3e2-30a3-4def-acd2-b4f7a1c6313a","title":"CVE-2026-82268: Qwen-Agent through 0.0.34 contains a server-side request forgery vulnerability in the document parsing path that treats ","summary":"Qwen-Agent versions up to 0.0.34 have a server-side request forgery vulnerability (SSRF, where an attacker tricks a server into making requests to unintended locations) in its document parsing feature that doesn't check where file paths actually point to. Attackers can access an unprotected Gradio interface (a tool for building AI demos) to make the server request data from internal systems, like metadata services, and then read that data through the parsed document output.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-82268","publishedAt":"2026-08-28T20:20:17.510Z","cveId":"CVE-2026-82268","cweIds":["CWE-918"],"cvssScore":"7.5","cvssSeverity":"high","severity":"high","attackType":["supply_chain"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["Qwen-Agent","Alibaba Qwen"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"network","attackComplexity":"low","privilegesRequired":"none","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-08-28T20:20:17.510Z","capecIds":["CAPEC-664"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"api","llmSpecific":true,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":["AML.T0010"]}}