PT-2026-44006 · 3Clyp50 · Agent-Zero

Yu Sun

·

Publicado

2026-05-27

·

Atualizado

2026-05-27

·

CVE-2026-47119

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Agent Zero before version 1.15 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary JavaScript in the application origin by serving SVG files through the image get API endpoint without Content-Security-Policy, X-Content-Type-Options, or Content-Disposition headers. Attackers can place a crafted SVG file containing script tags in any path readable by the agent-zero process and lure an authenticated user to the image get endpoint, causing the browser to execute the malicious script, steal the csrf token cookie, and perform unauthorized API calls on behalf of the victim.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-47119

Produtos afetados

Agent-Zero