PT-2026-44006 · 3Clyp50 · Agent-Zero

Yu Sun

·

Published

2026-05-27

·

Updated

2026-05-27

·

CVE-2026-47119

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Agent Zero before version 1.15 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary JavaScript in the application origin by serving SVG files through the image get API endpoint without Content-Security-Policy, X-Content-Type-Options, or Content-Disposition headers. Attackers can place a crafted SVG file containing script tags in any path readable by the agent-zero process and lure an authenticated user to the image get endpoint, causing the browser to execute the malicious script, steal the csrf token cookie, and perform unauthorized API calls on behalf of the victim.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-47119

Affected Products

Agent-Zero