{"id":"CVE-2026-86237","title":"A vulnerability was found in openagents-org openagents up to 0.8.19/0.9.3.post20","summary":"A vulnerability was found in openagents-org openagents up to 0.8.19/0.9.3.post20. Impacted is the function test_default_model of the file sdk/src/openagents/sdk/transports/http.py. Performing a manipulation of the argument base_url resul…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","cwe":["CWE-918"],"vendor":"openagents-org","product":"openagents","affected":["openagents 0.8.0","openagents 0.8.1","openagents 0.8.2","openagents 0.8.3","openagents 0.8.4","openagents 0.8.5","openagents 0.8.6","openagents 0.8.7","openagents 0.8.8","openagents 0.8.9","openagents 0.8.10","openagents 0.8.11","openagents 0.8.12","openagents 0.8.13","openagents 0.8.14","openagents 0.8.15","openagents 0.8.16","openagents 0.8.17","openagents 0.8.18","openagents 0.8.19","openagents 0.9.3.post20"],"published":"2026-09-07","updated":"2026-09-08","sourceUpdated":"2026-09-08T19:20:10.943","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-86237","references":[{"url":"https://github.com/openagents-org/openagents/","label":"cna@vuldb.com"},{"url":"https://github.com/openagents-org/openagents/issues/566","label":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-86237","label":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/898788","label":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/901667","label":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/399394","label":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/399394/cti","label":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/898788","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://vuldb.com/submit/901667","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","cve.org","exploit-available"],"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"yes","technicalImpact":"partial","timestamp":"2026-09-08T18:10:19.462751Z"},"epss":0.00514,"epssPercentile":0.42626,"ingestedAt":"2026-09-07T12:10:14.917Z","slug":"CVE-2026-86237","body":"## Overview\n\nA vulnerability was found in openagents-org openagents up to 0.8.19/0.9.3.post20. Impacted is the function test_default_model of the file sdk/src/openagents/sdk/transports/http.py. Performing a manipulation of the argument base_url results in server-side request forgery. The attack may be initiated remotely. The exploit has been made public and could be used. Endpoint and both sinks unchanged since filing; only the file moved (e277dd1a). Maintainer closed as inapplicable yet the identical unguarded code still ships in 0.9.3.post20. Sibling admin endpoints do call the shipped-but-unused-by-this-handler _require_admin().\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":29.2,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[{"seq":8335,"id":"CVE-2026-86237","ts":1788919998354,"field":"exploit_available","old":"false","new":"true"},{"seq":8144,"id":"CVE-2026-86237","ts":1788919289049,"field":"exploit_available","old":"true","new":"false"},{"seq":7953,"id":"CVE-2026-86237","ts":1788916360472,"field":"exploit_available","old":"false","new":"true"},{"seq":7762,"id":"CVE-2026-86237","ts":1788915306653,"field":"exploit_available","old":"true","new":"false"},{"seq":7571,"id":"CVE-2026-86237","ts":1788912721855,"field":"exploit_available","old":"false","new":"true"},{"seq":7380,"id":"CVE-2026-86237","ts":1788911339012,"field":"exploit_available","old":"true","new":"false"},{"seq":7184,"id":"CVE-2026-86237","ts":1788909080766,"field":"exploit_available","old":"false","new":"true"},{"seq":6996,"id":"CVE-2026-86237","ts":1788907395598,"field":"exploit_available","old":"true","new":"false"},{"seq":6798,"id":"CVE-2026-86237","ts":1788905446574,"field":"exploit_available","old":"false","new":"true"},{"seq":6616,"id":"CVE-2026-86237","ts":1788903462416,"field":"exploit_available","old":"true","new":"false"},{"seq":6402,"id":"CVE-2026-86237","ts":1788901812570,"field":"exploit_available","old":"false","new":"true"},{"seq":6232,"id":"CVE-2026-86237","ts":1788899563037,"field":"exploit_available","old":"true","new":"false"},{"seq":5994,"id":"CVE-2026-86237","ts":1788898181402,"field":"exploit_available","old":"false","new":"true"},{"seq":5883,"id":"CVE-2026-86237","ts":1788895712000,"field":"exploit_available","old":"true","new":"false"},{"seq":5777,"id":"CVE-2026-86237","ts":1788894573143,"field":"exploit_available","old":"false","new":"true"}]}