Описание
AgentAPI is an HTTP API for Claude Code, Goose, Aider, Gemini, Amp, and Codex. Versions 0.3.3 and below are susceptible to a client-side DNS rebinding attack when hosted over plain HTTP on localhost. An attacker can gain access to the /messages endpoint served by the Agent API. This allows for the unauthorized exfiltration of sensitive user data, specifically local message history, which can include secret keys, file system contents, and intellectual property the user was working on locally. This issue is fixed in version 0.4.0.
Ссылки
- Technical Description
- Patch
- Issue TrackingPatch
- Release Notes
- PatchVendor Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.4.0 (исключая)
cpe:2.3:a:coder:agentapi:*:*:*:*:*:*:*:*
EPSS
Процентиль: 19%
0.00059
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-350
CWE-290
Связанные уязвимости
CVSS3: 6.5
github
4 месяца назад
Coder AgentAPI exposed user chat history via a DNS rebinding attack
EPSS
Процентиль: 19%
0.00059
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-350
CWE-290