A weakness has been identified in frdel/agent0ai agent-zero 0.9.7. This affects the function handle_pdf_document of the file python/helpers/document_query.py. This manipulation causes server-side request forgery. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
History

Tue, 17 Mar 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 17 Mar 2026 04:15:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in frdel/agent0ai agent-zero 0.9.7. This affects the function handle_pdf_document of the file python/helpers/document_query.py. This manipulation causes server-side request forgery. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Title frdel/agent0ai agent-zero document_query.py handle_pdf_document server-side request forgery
First Time appeared Agent-zero
Agent-zero agent-zero
Weaknesses CWE-918
CPEs cpe:2.3:a:agent-zero:agent-zero:*:*:*:*:*:*:*:*
Vendors & Products Agent-zero
Agent-zero agent-zero
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2026-03-17T04:02:07.980Z

Updated: 2026-03-17T13:22:56.803Z

Reserved: 2026-03-16T21:31:55.971Z

Link: CVE-2026-4308

cve-icon Vulnrichment

Updated: 2026-03-17T13:22:53.422Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-03-17T04:16:24.207

Modified: 2026-03-17T14:20:01.670

Link: CVE-2026-4308

cve-icon Redhat

No data.