CVE-2026-82275: Qwen-Agent through 0.0.34 contains a path traversal vulnerability in the document parser that fails to restrict file acc
Summary
Qwen-Agent versions up to 0.0.34 have a path traversal vulnerability (a flaw that lets attackers access files outside the intended directory) in its document parser. Attackers can use the unprotected Gradio interface (a web tool for sharing AI models) to read any files that the server has access to by providing file paths.
Vulnerability Details
7.5(high)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
network
low
none
none
August 28, 2026
Classification
Affected Vendors
Related Issues
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-82275
First tracked: August 28, 2026 at 08:08 PM
Classified by LLM (prompt v3) · confidence: 92%