CVE-2026-67346: Server-Side Request Forgery (SSRF) in kyegomez swarms
A server-side request forgery (SSRF) vulnerability exists in kyegomez swarms through version 6.8.1. The vulnerability is due to improper hostname validation in the _is_safe_url function, which fails to correctly validate hostnames via DNS resolution. This allows attackers to bypass blocklists by supplying URLs that resolve to internal, private, loopback, or metadata IP addresses. The issue was fixed in a commit identified as 8b0fc9e. The vulnerability has a high severity rating with a CVSS score of 7.7.
AI Analysis
Technical Summary
CVE-2026-67346 is a server-side request forgery vulnerability affecting kyegomez swarms versions up to and including 6.8.1. The root cause is a failure in the _is_safe_url function to properly validate hostnames through DNS resolution, enabling attackers to bypass hostname blocklists. By providing user-controlled image or audio URLs that resolve to internal network addresses such as private, loopback, or metadata IPs, attackers can cause the server to make unauthorized requests to internal services, potentially leading to credential exfiltration. The vulnerability was addressed in commit 8b0fc9e, which presumably corrects the hostname validation logic.
Potential Impact
An attacker can exploit this SSRF vulnerability to make the vulnerable server perform unauthorized requests to internal network resources, including private, loopback, or metadata endpoints. This can lead to unauthorized access to internal services and exfiltration of sensitive credentials or information. The vulnerability does not require privileges or user interaction and has a high impact on confidentiality due to potential credential exposure.
Mitigation Recommendations
A fix for this vulnerability is available and was implemented in commit 8b0fc9e. Users should upgrade to a version of swarms that includes this commit or later. Since the product is not a cloud service, remediation requires applying the official fix. Patch status is not explicitly confirmed in the advisory, so users should verify the presence of the fix in their deployed version. Until patched, avoid processing untrusted URLs that could resolve to internal addresses.
CVE-2026-67346: Server-Side Request Forgery (SSRF) in kyegomez swarms
Description
A server-side request forgery (SSRF) vulnerability exists in kyegomez swarms through version 6.8.1. The vulnerability is due to improper hostname validation in the _is_safe_url function, which fails to correctly validate hostnames via DNS resolution. This allows attackers to bypass blocklists by supplying URLs that resolve to internal, private, loopback, or metadata IP addresses. The issue was fixed in a commit identified as 8b0fc9e. The vulnerability has a high severity rating with a CVSS score of 7.7.
CVSS v4.0
Score 7.7high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-67346 is a server-side request forgery vulnerability affecting kyegomez swarms versions up to and including 6.8.1. The root cause is a failure in the _is_safe_url function to properly validate hostnames through DNS resolution, enabling attackers to bypass hostname blocklists. By providing user-controlled image or audio URLs that resolve to internal network addresses such as private, loopback, or metadata IPs, attackers can cause the server to make unauthorized requests to internal services, potentially leading to credential exfiltration. The vulnerability was addressed in commit 8b0fc9e, which presumably corrects the hostname validation logic.
Potential Impact
An attacker can exploit this SSRF vulnerability to make the vulnerable server perform unauthorized requests to internal network resources, including private, loopback, or metadata endpoints. This can lead to unauthorized access to internal services and exfiltration of sensitive credentials or information. The vulnerability does not require privileges or user interaction and has a high impact on confidentiality due to potential credential exposure.
Mitigation Recommendations
A fix for this vulnerability is available and was implemented in commit 8b0fc9e. Users should upgrade to a version of swarms that includes this commit or later. Since the product is not a cloud service, remediation requires applying the official fix. Patch status is not explicitly confirmed in the advisory, so users should verify the presence of the fix in their deployed version. Until patched, avoid processing untrusted URLs that could resolve to internal addresses.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-07-29T13:09:45.993Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a6b8fac9c2644c7f87317ae
Added to database: 07/30/2026, 17:53:48 UTC
Last enriched: 07/30/2026, 18:07:00 UTC
Last updated: 07/30/2026, 18:11:13 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.