Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v37m-33r4-9ggf

Опубликовано: 30 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.7
CVSS3: 8.6

Описание

Swarms through 6.8.1, fixed in commit 8b0fc9e, contains a server-side request forgery vulnerability in the _is_safe_url function that fails to validate hostnames through DNS resolution, allowing attackers to bypass the blocklist. Attackers can supply user-controlled image or audio URLs that resolve to private, loopback, or metadata addresses to reach internal services and exfiltrate credentials.

Swarms through 6.8.1, fixed in commit 8b0fc9e, contains a server-side request forgery vulnerability in the _is_safe_url function that fails to validate hostnames through DNS resolution, allowing attackers to bypass the blocklist. Attackers can supply user-controlled image or audio URLs that resolve to private, loopback, or metadata addresses to reach internal services and exfiltrate credentials.

EPSS

Процентиль: 21%
0.0029
Низкий

7.7 High

CVSS4

8.6 High

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 8.6
nvd
7 дней назад

Swarms through 6.8.1, fixed in commit 8b0fc9e, contains a server-side request forgery vulnerability in the _is_safe_url function that fails to validate hostnames through DNS resolution, allowing attackers to bypass the blocklist. Attackers can supply user-controlled image or audio URLs that resolve to private, loopback, or metadata addresses to reach internal services and exfiltrate credentials.

EPSS

Процентиль: 21%
0.0029
Низкий

7.7 High

CVSS4

8.6 High

CVSS3

Дефекты

CWE-918