๐Ÿ” CVE Alert

CVE-2026-86237

MEDIUM 5.3

openagents-org openagents http.py test_default_model server-side request forgery

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability was found in openagents-org openagents up to 0.8.19/0.9.3.post20. Impacted is the function test_default_model of the file sdk/src/openagents/sdk/transports/http.py. Performing a manipulation of the argument base_url results in server-side request forgery. The attack may be initiated remotely. The exploit has been made public and could be used. Endpoint and both sinks unchanged since filing; only the file moved (e277dd1a). Maintainer closed as inapplicable yet the identical unguarded code still ships in 0.9.3.post20. Sibling admin endpoints do call the shipped-but-unused-by-this-handler _require_admin().

CWE CWE-918
Vendor openagents-org
Product openagents
Published Sep 7, 2026
Last Updated Sep 8, 2026
Stay Ahead of the Next One

Get instant alerts for openagents-org openagents

Be the first to know when new medium vulnerabilities affecting openagents-org openagents are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

openagents-org / openagents
0.8.0 0.8.1 0.8.2 0.8.3 0.8.4 0.8.5 0.8.6 0.8.7 0.8.8 0.8.9 0.8.10 0.8.11 0.8.12 0.8.13 0.8.14 0.8.15 0.8.16 0.8.17 0.8.18 0.8.19 0.9.3.post20

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/399394 vuldb.com: https://vuldb.com/vuln/399394/cti vuldb.com: https://vuldb.com/cve/CVE-2026-86237 vuldb.com: https://vuldb.com/submit/898788 vuldb.com: https://vuldb.com/submit/901667 github.com: https://github.com/openagents-org/openagents/issues/566 github.com: https://github.com/openagents-org/openagents/

Credits

๐Ÿ” yangzhongjie (VulDB User) VulDB CNA Team