PatchSiren

openagents-org CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM openagents-org CVE published 2026-09-07

CVE-2026-86237

A vulnerability was found in openagents-org openagents up to 0.8.19/0.9.3.post20. Impacted is the function test_default_model of the file sdk/src/openagents/sdk/transports/http.py. Performing a manipulation of the argument base_url results in server-side request forgery. The attack may be initiated remotely. This vulnerability affects openagents-org openagents deployments. Defenders should verify the pres [truncated]