top of page
perceptive_background_267k.jpg

Swarms through 6.8.1, fixed in commit 8b0fc9e, contains a server-side request forgery vulnerability in the _is_safe_url function that fails to validate hostname…

Published:

29 juli 2026 om 22:00:00

Alert date:

30 juli 2026 om 16:04:07

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Supply Chain & Dependencies, Data Breach & Exfiltration

Swarms versions through 6.8.1 contain a server-side request forgery (SSRF) vulnerability in the _is_safe_url function. The function fails to validate hostnames through DNS resolution, allowing attackers to bypass the blocklist. Attackers can supply user-controlled image or audio URLs that resolve to private, loopback, or metadata addresses. This enables attackers to reach internal services and potentially exfiltrate credentials. The vulnerability was fixed in commit 8b0fc9e. The issue is tracked as CVE-2026-67346 and is documented in GitHub issue #1714 and pull request #1734. The attack vector leverages DNS rebinding techniques to circumvent URL safety checks. Users should update to a version incorporating commit 8b0fc9e or later.

Technical details

Mitigation steps:

Affected products:

Swarms 6.8.1 and earlier

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page