{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aalibabaqwen-agent/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:alibaba:qwen-agent:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-82268"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Qwen-Agent (\u003c= 0.0.34)"],"_cs_severities":["high"],"_cs_tags":["ssrf","vulnerability","cloud","path-traversal","arbitrary-file-read","web-application-vulnerability"],"_cs_type":"advisory","_cs_vendors":["Alibaba"],"content_html":"\u003cp\u003eQwen-Agent, an open-source agent framework, contains a server-side request forgery (SSRF) vulnerability identified as CVE-2026-82268 affecting versions through 0.0.34. The flaw exists within the document parsing functionality, which fails to adequately validate or restrict caller-supplied paths. Specifically, the application processes these paths as URLs without enforcing scheme restrictions or host validation. An unauthenticated attacker can exploit this behavior by manipulating the document parsing input to interact with the server's local environment, including internal Gradio interfaces or cloud-provider metadata services. This enables the attacker to force the server to issue arbitrary HTTP requests and potentially read returned data, which is subsequently surfaced through the application's document parsing output. This vulnerability presents a high risk for environments where Qwen-Agent is deployed with access to internal network resources or sensitive cloud service endpoints.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to bypass network boundaries and interact with internal services that are not exposed to the public internet. This can lead to the exfiltration of sensitive information, such as cloud metadata, internal configuration details, or credentials, which may facilitate further compromise of the underlying infrastructure or internal services.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade to a version of Qwen-Agent that addresses CVE-2026-82268 once available.\u003c/li\u003e\n\u003cli\u003eRestrict network access for servers hosting Qwen-Agent to prevent them from reaching internal metadata services (e.g., 169.254.169.254) or sensitive administrative endpoints.\u003c/li\u003e\n\u003cli\u003eImplement strict input validation on all document parsing paths to ensure only expected URLs or local file paths are processed.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-28T21:38:24Z","date_published":"2026-08-28T21:38:01Z","id":"https://feed.craftedsignal.io/briefs/2026-08-qwen-agent-ssrf/","summary":"Qwen-Agent version 0.0.34 and earlier contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated attackers to force the server to perform arbitrary internal HTTP requests and exfiltrate metadata service content.","title":"SSRF Vulnerability in Qwen-Agent Document Parsing","url":"https://feed.craftedsignal.io/briefs/2026-08-qwen-agent-ssrf/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:alibaba:qwen-Agent:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}