Impact
The vulnerability arises from improper handling of the tool_name and tool_params arguments in the get_file_content function within the server.py component of heshengtao's super‑agent‑party. The flaw allows an attacker to manipulate these arguments and retrieve sensitive file content from the server. The issue is classified as an information exposure (CWE‑200) and an improper authorization (CWE‑284) problem, enabling remote exploitation without requiring local access.
Affected Systems
The affected product is heshengtao's super‑agent‑party, versions up to and including 0.4.1. No other versions are currently reported as vulnerable.
Risk and Exploitability
The CVSS score for this vulnerability is 6.9, indicating medium risk. Attackers can launch the exploit remotely, and public proof‑of‑concept code is available. While the vulnerability is not listed in the CISA KEV catalog and an EPSS score is not available, the fact that the exploit is publicly available increases its real‑world threat. Without an official vendor response, susceptible installations remain at a measurable risk of data exposure.
OpenCVE Enrichment