CVE-2026-4308 identifies a Server-Side Request Forgery (SSRF) vulnerability in frdel/agent0ai agent-zero version 0.9.7, specifically within the handle_pdf_document function. This medium-severity flaw (CVSS 6.3) allows for remote exploitation with low attack complexity, potentially impacting confidentiality, integrity, and availability. Although there is no evidence of active exploitation or inclusion in the KEV catalog, a public exploit has been made available. Community discussion and media coverage regarding this vulnerability are currently minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Agent0ai | Agent-Zero | 0.9.7CNA affected | |
| Frdel | Agent-Zero | 0.9.7CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.