PT-2026-44006 · 3Clyp50 · Agent-Zero
Yu Sun
·
Published
2026-05-27
·
Updated
2026-05-27
·
CVE-2026-47119
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Agent Zero before version 1.15 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary JavaScript in the application origin by serving SVG files through the image get API endpoint without Content-Security-Policy, X-Content-Type-Options, or Content-Disposition headers. Attackers can place a crafted SVG file containing script tags in any path readable by the agent-zero process and lure an authenticated user to the image get endpoint, causing the browser to execute the malicious script, steal the csrf token cookie, and perform unauthorized API calls on behalf of the victim.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Agent-Zero