CVE-2026-86237: openagents-org openagents http.py test_default_model server-side request forgery

Published Sep 7, 2026
·
Updated

A vulnerability was found in openagents-org openagents up to 0.8.19/0.9.3.post20. Impacted is the function testdefaultmodel of the file sdk/src/openagents/sdk/transports/http.py. Performing a manipulation of the argument baseurl results in server-side request forgery. The attack may be initiated remotely. The exploit has been made public and could be used. Endpoint and both sinks unchanged since filing; only the file moved (e277dd1a). Maintainer closed as inapplicable yet the identical unguarded code still ships in 0.9.3.post20. Sibling admin endpoints do call the shipped-but-unused-by-this-handler requireadmin().

Affected Software

1 affected component
openagents-org/openagents<=0.8.19, =0.9.3.post20

Event History

Sep 7, 2026
CVE Published
via MITRE·12:15 AM
Data Sourced
via MITRE·12:15 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments should be prioritized for triage?

Deployments running openagents versions up to 0.8.19 or 0.9.3.post20 should be assessed, particularly where remote users can reach the handler that invokes test_default_model. The issue can be initiated remotely and requires no privileges or user interaction according to the supplied vector.

2

What must an attacker be able to control?

An attacker needs to manipulate the base_url argument passed to test_default_model in sdk/src/openagents/sdk/transports/http.py. This causes the server to make a request to an attacker-selected destination.

3

Is there evidence that this handler enforces the available admin authorization check?

No. The supplied information states that sibling administrative endpoints call _require_admin(), but this handler does not use that shipped authorization check.

4

How can we assess whether our code is still affected?

Review the implementation of test_default_model and its reachable endpoint for unguarded use of base_url, and verify whether _require_admin() is invoked for that path. The report states that the endpoint and both SSRF sinks remained unchanged through 0.9.3.post20, despite the file having moved.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203