CVE-2026-18974
heshengtao super-agent-party execute_tool_manually Endpoint server.py get_file_content information disclosure
CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th
A vulnerability was found in heshengtao super-agent-party up to 0.4.1. This affects the function get_file_content of the file server.py of the component execute_tool_manually Endpoint. The manipulation of the argument tool_name/tool_params results in information disclosure. The attack can be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
| CWE | CWE-200 CWE-284 |
| Vendor | heshengtao |
| Product | super-agent-party |
| Published | Aug 6, 2026 |
Stay Ahead of the Next One
Get instant alerts for heshengtao super-agent-party
Be the first to know when new medium vulnerabilities affecting heshengtao super-agent-party are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
heshengtao / super-agent-party
0.4.0 0.4.1
References
vuldb.com: https://vuldb.com/vuln/386263 vuldb.com: https://vuldb.com/vuln/386263/cti vuldb.com: https://vuldb.com/cve/CVE-2026-18974 vuldb.com: https://vuldb.com/submit/862457 vuldb.com: https://vuldb.com/submit/862575 gist.github.com: https://gist.github.com/YLChen-007/479bfabb441bd6cc5337db910b004841
Credits
๐ Erichen-x (VulDB User) VulDB CNA Team