AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T01:16:29.587Z and has not been modified since then. The vulnerability affects heshengtao super-agent-party up to 0.4.1, specifically the get_file_content function in server.py, allowing for information disclosure and can be exploited remotely with a CVSS score of 5.5, indicating medium severity. [truncated]
The CVE-2026-18973 vulnerability is a server-side request forgery (SSRF) issue in the heshengtao super-agent-party up to version 0.4.1. This vulnerability allows an attacker to manipulate the url argument in the sanitize_proxy_url function of the server.py file within the extension_proxy Route component, leading to SSRF attacks. The attack can be initiated remotely, and the exploit has been publicly discl [truncated]