


Perceptive Security
SOC/SIEM Consultancy

A vulnerability has been found in heshengtao super-agent-party up to 0.4.1. The impacted element is the function sanitize_proxy_url of the file server.py of the…
Published:
6 August 2026 at 00:00:00
Alert date:
6 August 2026 at 04:00:35
Source:
nvd.nist.gov
Web Technologies, Zero-Day Vulnerabilities
A server-side request forgery (SSRF) vulnerability has been identified in heshengtao super-agent-party up to version 0.4.1. The flaw exists in the sanitize_proxy_url function within server.py, part of the extension_proxy Route component. An attacker can manipulate the url argument to trigger SSRF, allowing remote exploitation. The vulnerability has been publicly disclosed with a working exploit available. The vendor was notified but did not respond to the disclosure. No patch or mitigation has been confirmed from the vendor side.
Technical details
Mitigation steps:
Affected products:
heshengtao super-agent-party up to 0.4.1
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-18973
https://gist.github.com/YLChen-007/2f12ffb785d975b46b73896c0fb8cb5d
https://vuldb.com/cve/CVE-2026-18973
https://vuldb.com/submit/862456
https://vuldb.com/submit/862458
https://vuldb.com/submit/862570
https://vuldb.com/submit/862608
https://vuldb.com/vuln/386262
https://vuldb.com/vuln/386262/cti
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
