{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/super-agent-party/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-18973"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["super-agent-party"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"threat","_cs_vendors":["heshengtao"],"content_html":"\u003cp\u003eA high-severity Server-Side Request Forgery (SSRF) vulnerability (CVE-2026-18973) has been identified in the heshengtao super-agent-party project in versions up to and including 0.4.1. The flaw resides in the \u003ccode\u003esanitize_proxy_url\u003c/code\u003e function located within the \u003ccode\u003eserver.py\u003c/code\u003e file of the \u003ccode\u003eextension_proxy\u003c/code\u003e component. The application fails to properly sanitize the \u003ccode\u003eurl\u003c/code\u003e argument, allowing an unauthenticated remote attacker to influence the proxy's request target. This vulnerability can be exploited to force the application server to make arbitrary requests to internal network resources or external services, potentially leading to information disclosure or reconnaissance of internal services inaccessible to the attacker. A public proof-of-concept exploit is available, increasing the risk of active exploitation.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify instances of super-agent-party running in the target environment.\u003c/li\u003e\n\u003cli\u003eAttacker crafts an HTTP request targeting the \u003ccode\u003eextension_proxy\u003c/code\u003e route.\u003c/li\u003e\n\u003cli\u003eAttacker injects a malicious payload into the \u003ccode\u003eurl\u003c/code\u003e argument of the request.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003esanitize_proxy_url\u003c/code\u003e function in \u003ccode\u003eserver.py\u003c/code\u003e fails to perform adequate input validation on the user-supplied \u003ccode\u003eurl\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe server executes an outbound network request to an internal target (e.g., local cloud metadata services or internal APIs) based on the malicious URL.\u003c/li\u003e\n\u003cli\u003eThe application processes the response from the internal service and potentially returns the data to the attacker, completing the exfiltration or reconnaissance phase.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows for SSRF, which can be leveraged to bypass network boundaries, access internal services, or query sensitive local cloud metadata endpoints. If the application server has elevated privileges or network access within the internal infrastructure, an attacker could escalate their access or gain further information about the network topology, potentially impacting the confidentiality and integrity of protected systems.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpdate heshengtao super-agent-party to the latest available version beyond 0.4.1 that incorporates the fix for CVE-2026-18973.\u003c/li\u003e\n\u003cli\u003eImplement network segmentation and egress filtering on servers running super-agent-party to restrict the proxy's ability to reach sensitive internal subnets or local metadata endpoints (e.g., 169.254.169.254).\u003c/li\u003e\n\u003cli\u003eDeploy web application firewall (WAF) rules to inspect and filter requests targeting the \u003ccode\u003eextension_proxy\u003c/code\u003e path containing suspicious characters or internal URI schemes.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-08-06T01:21:30Z","date_published":"2026-08-06T01:21:30Z","id":"https://feed.craftedsignal.io/briefs/2026-08-super-agent-party-ssrf/","summary":"A server-side request forgery (SSRF) vulnerability in heshengtao super-agent-party (up to version 0.4.1) allows remote attackers to perform unauthorized requests via the sanitize_proxy_url function.","title":"SSRF Vulnerability in heshengtao super-agent-party","url":"https://feed.craftedsignal.io/briefs/2026-08-super-agent-party-ssrf/"}],"language":"en","title":"CraftedSignal Threat Feed - Super-Agent-Party","version":"https://jsonfeed.org/version/1.1"}