


Perceptive Security
SOC/SIEM Consultancy

Swarms through 6.8.1, fixed in commit 8b0fc9e, contains a server-side request forgery vulnerability in the _is_safe_url function that fails to validate hostname…
Published:
29 juli 2026 om 22:00:00
Alert date:
30 juli 2026 om 16:04:07
Source:
nvd.nist.gov
Web Technologies, Supply Chain & Dependencies, Data Breach & Exfiltration
Swarms versions through 6.8.1 contain a server-side request forgery (SSRF) vulnerability in the _is_safe_url function. The function fails to validate hostnames through DNS resolution, allowing attackers to bypass the blocklist. Attackers can supply user-controlled image or audio URLs that resolve to private, loopback, or metadata addresses. This enables attackers to reach internal services and potentially exfiltrate credentials. The vulnerability was fixed in commit 8b0fc9e. The issue is tracked as CVE-2026-67346 and is documented in GitHub issue #1714 and pull request #1734. The attack vector leverages DNS rebinding techniques to circumvent URL safety checks. Users should update to a version incorporating commit 8b0fc9e or later.
Technical details
Mitigation steps:
Affected products:
Swarms 6.8.1 and earlier
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-67346
https://github.com/kyegomez/swarms/commit/8b0fc9e4645603ad94d5fcf4da86e3b9c71f4743
https://github.com/kyegomez/swarms/issues/1714
https://github.com/kyegomez/swarms/pull/1734
https://www.vulncheck.com/advisories/swarms-server-side-request-forgery-via-dns-rebinding-bypass
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
