What is CVE-2026-18973?
This CVE is a Server-Side Request Forgery (SSRF) vulnerability found in the sanitize_proxy_url function of server.py within the extension_proxy Route component of heshengtao super-agent-party up to version 0.4.1. The flaw allows remote attackers to manipulate the url argument, potentially leading to unauthorized actions. Affected users should immediately update to the latest version or implement input restrictions.
Azərbaycanca: Bu CVE, heshengtao super-agent-party proqramının 0.4.1-ə qədər versiyalarında server.py faylındakı extension_proxy Route komponentinin sanitize_proxy_url funksiyasında aşkar edilmiş Server-Side Request Forgery (SSRF) zəifliyidir. Hücumçu url arqumentini manipulyasiya edərək uzaqdan zərərli əməliyyatlar apara bilər. Təsirə məruz qalan istifadəçilər dərhal proqramı ən son versiyaya yeniləməli və ya giriş məhdudiyyətləri tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
In which component of which software was CVE-2026-18973 discovered?
The vulnerability was discovered in the sanitize_proxy_url function of server.py within the extension_proxy Route component of heshengtao super-agent-party.
What should users affected by CVE-2026-18973 do?
Affected users should immediately update to the latest version or implement input restrictions.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.