CVE-2026-82275 is a path traversal vulnerability in Qwen-Agent through version 0.0.34, affecting the document parser. The vulnerability allows unauthenticated attackers to read arbitrary files accessible by the server process via the Gradio interface by supplying absolute file paths. This vulnerability has a high CVSS score of 8.7, indicating a high severity. Defenders and administrators of systems using [truncated]
CVE-2026-82268 is a server-side request forgery vulnerability in Qwen-Agent through version 0.0.34. The vulnerability is located in the document parsing path and allows attackers to make the server issue HTTP requests to arbitrary internal addresses, including metadata services, without scheme restriction or host validation. This is achieved by treating caller-supplied paths as URLs. The unauthenticated G [truncated]