CVE-2026-82268 – Qwen-Agent
CVSS 7.5
IMPORTANT
Zero Day – Immediate Deployment
“An exposed document parser can become a direct path to internal services and sensitive server files.”
Qwen-Agent through version 0.0.34 contains two High-severity vulnerabilities in its unauthenticated Gradio document parsing interface. CVE-2026-82268 allows server-side request forgery by treating attacker-supplied paths as unrestricted URLs, enabling access to internal services and metadata endpoints. The CVSS score is 7.5, which is High severity.
CVE-2026-82275 allows path traversal through absolute file paths, exposing arbitrary files readable by the Qwen-Agent server process. The CVSS score is 7.5, which is High severity. Public proof-of-concept material is available for both vulnerabilities.
Key Details
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-918
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.