Impact
The vulnerability is located in the sanitize_proxy_url function of the extension_proxy Route within server.py, allowing a supplied URL to be processed by the server. This manipulation results in server‑side request forgery, letting an attacker cause the application to make arbitrary HTTP requests to internal or external resources. The primary impact is the potential for unauthorized access to internal systems or information leakage, assuming the application ignores SSRF mitigations. The flaw is identified as CWE‑918.
Affected Systems
The product heshengtao super‑agent‑party with any version up to and including 0.4.1 is affected.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity. No EPSS data is available, yet the vulnerability is publicly disclosed and can be triggered remotely, with no authentication requirement noted in the description. Although it is not listed in the CISA KEV catalog, the ability to target internal networks makes it an attractive vector for attackers when the vulnerable component is exposed to the internet.
OpenCVE Enrichment