PT-2026-44006 · 3Clyp50+1 · Agent-Zero

·

CVE-2026-47119

·

Published

2026-05-27

·

Updated

2026-05-27

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Agent Zero versions prior to 1.15
Description A stored cross-site scripting issue exists where attackers can execute arbitrary JavaScript within the application origin. This occurs when SVG files are served through the 'image get' API endpoint without Content-Security-Policy, X-Content-Type-Options, or Content-Disposition headers. An attacker can place a crafted SVG file containing script tags in a path readable by the agent-zero process and lure an authenticated user to the 'image get' endpoint. This allows the browser to execute the malicious script, steal the csrf token cookie, and perform unauthorized API calls on behalf of the victim.
Recommendations Update Agent Zero to version 1.15 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-47119

Affected Products

Agent-Zero