PatchSiren

QwenLM CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH QwenLM CVE published 2026-08-28

CVE-2026-82275

CVE-2026-82275 is a path traversal vulnerability in Qwen-Agent through version 0.0.34, affecting the document parser. The vulnerability allows unauthenticated attackers to read arbitrary files accessible by the server process via the Gradio interface by supplying absolute file paths. This vulnerability has a high CVSS score of 8.7, indicating a high severity. Defenders and administrators of systems using [truncated]

HIGH QwenLM CVE published 2026-08-28

CVE-2026-82268

CVE-2026-82268 is a server-side request forgery vulnerability in Qwen-Agent through version 0.0.34. The vulnerability is located in the document parsing path and allows attackers to make the server issue HTTP requests to arbitrary internal addresses, including metadata services, without scheme restriction or host validation. This is achieved by treating caller-supplied paths as URLs. The unauthenticated G [truncated]