


Perceptive Security
SOC/SIEM Consultancy

Swarms through 6.8.1, fixed in commit 8b0fc9e, contains a server-side request forgery vulnerability in the _is_safe_url function that fails to validate hostname…
Published:
29 juli 2026 om 22:00:00
Alert date:
30 juli 2026 om 17:11:53
Source:
nvd.nist.gov
Web Technologies, Data Breach & Exfiltration, Supply Chain & Dependencies
Swarms versions through 6.8.1 contain a server-side request forgery (SSRF) vulnerability in the _is_safe_url function. The function fails to validate hostnames through DNS resolution, allowing attackers to bypass the blocklist. Attackers can supply user-controlled image or audio URLs that resolve to private, loopback, or metadata addresses. This enables attackers to reach internal services and potentially exfiltrate credentials. The vulnerability was fixed in commit 8b0fc9e. The flaw is classified as a DNS rebinding bypass technique. It poses a high risk due to potential credential exfiltration and access to internal infrastructure. Users should update to the patched version immediately.
Technical details
Mitigation steps:
Affected products:
Swarms 6.8.1
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-67346
https://github.com/kyegomez/swarms/commit/8b0fc9e4645603ad94d5fcf4da86e3b9c71f4743
https://github.com/kyegomez/swarms/issues/1714
https://github.com/kyegomez/swarms/pull/1734
https://www.vulncheck.com/advisories/swarms-server-side-request-forgery-via-dns-rebinding-bypass
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
