What is CVE-2026-18974?
This vulnerability affects super-agent-party up to version 0.4.1, specifically the get_file_content function in the execute_tool_manually endpoint. Manipulation of tool_name/tool_params arguments can lead to information disclosure. Updating to the latest version is recommended to address the issue.
Azərbaycanca: Bu boşluq super-agent-party (versiya 0.4.1-ə qədər) alətinin execute_tool_manually endpointindəki get_file_content funksiyasında aşkarlanıb. tool_name/tool_params arqumentlərinin manipulyasiyası informasiya sızmasına səbəb olur. Bu problemi aradan qaldırmaq üçün ən son versiyaya yenilənmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Which versions of super-agent-party are affected by CVE-2026-18974?
This vulnerability affects super-agent-party up to version 0.4.1.
How can the CVE-2026-18974 vulnerability be fixed?
To fix this issue, it is recommended to update super-agent-party to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.