A weakness has been identified in frdel/agent0ai agent-zero 0.9.7. This affects the function handle_pdf_document of the file python/helpers/document_query.py. This manipulation causes server-side request forgery. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

Project Subscriptions

Vendors Products
Agent-zero Subscribe
Agent-zero Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 17 Mar 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 17 Mar 2026 04:15:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in frdel/agent0ai agent-zero 0.9.7. This affects the function handle_pdf_document of the file python/helpers/document_query.py. This manipulation causes server-side request forgery. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Title frdel/agent0ai agent-zero document_query.py handle_pdf_document server-side request forgery
First Time appeared Agent-zero
Agent-zero agent-zero
Weaknesses CWE-918
CPEs cpe:2.3:a:agent-zero:agent-zero:*:*:*:*:*:*:*:*
Vendors & Products Agent-zero
Agent-zero agent-zero
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-03-17T13:22:56.803Z

Reserved: 2026-03-16T21:31:55.971Z

Link: CVE-2026-4308

cve-icon Vulnrichment

Updated: 2026-03-17T13:22:53.422Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-03-17T04:16:24.207

Modified: 2026-03-17T14:20:01.670

Link: CVE-2026-4308

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-17T09:51:56Z

Weaknesses