CVE-2026-82275 – Qwen-Agent

CVSS 7.5 IMPORTANT Zero Day – Immediate Deployment

“An exposed document parser can become a direct path to internal services and sensitive server files.”

Qwen-Agent through version 0.0.34 contains two High-severity vulnerabilities in its unauthenticated Gradio document parsing interface. CVE-2026-82268 allows server-side request forgery by treating attacker-supplied paths as unrestricted URLs, enabling access to internal services and metadata endpoints. The CVSS score is 7.5, which is High severity.

CVE-2026-82275 allows path traversal through absolute file paths, exposing arbitrary files readable by the Qwen-Agent server process. The CVSS score is 7.5, which is High severity. Public proof-of-concept material is available for both vulnerabilities.

Key Details

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-22
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.