Impact
A security weakness exists in the _dispatch_notification function of a2a‑python’s Push Notification Sender; the push_info.url argument can be controlled by an attacker, causing the application to issue arbitrary HTTP requests. This server‑side request forgery (CWE‑918) allows a remote attacker to trigger outbound traffic to any destination reachable from the host, creating opportunities to exfiltrate data, access internal services, or perform denial‑of‑service attacks against back‑end systems.
Affected Systems
All installations of the a2aproject a2a‑python component running version 1.1.3 or earlier are affected. The flaw is remedied in release 1.1.4, which implements input validation to restrict the destination URL.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and no EPSS data is currently available. The vulnerability is not listed in the CISA KEV catalog. Attackers can trigger it remotely without authentication and can manipulate outbound connections, making it a useful vector for further internal exploitation given the application's network reach.
OpenCVE Enrichment