Threats Tagged 'cve-2026-18973'
View all threats tagged with 'cve-2026-18973'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-18973'
Click on any threat for detailed analysis and mitigation recommendations
A server-side request forgery (SSRF) vulnerability exists in the sanitize_proxy_url function of the server.py file within the extension_proxy Route component of heshengtao super-agent-party up to version 0.4.1. This vulnerability allows remote attackers to manipulate the url argument, potentially causing unauthorized requests from the server. The vulnerability has been publicly disclosed, but the vendor has not responded or provided a fix. No patch or remediation is currently available. Join the discussion | GCVE Database | 08/06/2026, 00:30:12 UTC Added: 08/06/2026, 18:17:15 UTC |
CVE-2026-18973 is a server-side request forgery (SSRF) vulnerability in the heshengtao super-agent-party software, specifically in the sanitize_proxy_url function within the extension_proxy Route component. This vulnerability affects versions 0.4.0 and 0.4.1 and can be exploited remotely without authentication. The vulnerability has been publicly disclosed, but no official vendor response or patch is available. Join the discussion | CVE Database V5 | 08/06/2026, 00:30:12 UTC Added: 08/06/2026, 00:56:46 UTC |
Showing 1 to 2 of 2 results