PT-2026-44006 · 3Clyp50+1 · Agent-Zero
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Agent Zero versions prior to 1.15
Description
A stored cross-site scripting issue exists where attackers can execute arbitrary JavaScript within the application origin. This occurs when SVG files are served through the 'image get' API endpoint without Content-Security-Policy, X-Content-Type-Options, or Content-Disposition headers. An attacker can place a crafted SVG file containing script tags in a path readable by the agent-zero process and lure an authenticated user to the 'image get' endpoint. This allows the browser to execute the malicious script, steal the
csrf token cookie, and perform unauthorized API calls on behalf of the victim.Recommendations
Update Agent Zero to version 1.15 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Agent-Zero