Vulnerability  ·  2026-08-08

super-agent-party — SSRF in Extension Proxy Route

VulnerabilityMedium impactGlobalCVE-2026-18973
NVD published CVE-2026-18973 (CVSS 7.3, High) on August 6, 2026, and public PoC/exploit details were disclosed for an SSRF flaw in the extension-proxy component of the super-agent-party framework.
SSRF in an agent's extension/plugin proxy can be used to pivot into internal cloud metadata services or internal-only APIs, a common path to credential theft in cloud-hosted agent deployments.
The sanitize_proxy_url function in the extension_proxy route detects private-network targets but only logs rather than rejecting them, allowing a remote attacker to force the server to make arbitrary internal HTTP requests (SSRF).
heshengtao super-agent-party ≤ 0.4.1
Upgrade to a patched super-agent-party release; block outbound requests to private IP ranges at the network layer as a compensating control.
NVD CVE-2026-18973Positive Technologies dbugs
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →