High severity7.5NVD Advisory· Published Aug 28, 2026
CVE-2026-82275
CVE-2026-82275
Description
Qwen-Agent through 0.0.34 contains a path traversal vulnerability in the document parser that fails to restrict file access to intended directories. Attackers can supply absolute file paths to the unauthenticated Gradio interface to read arbitrary files accessible by the server process.
Affected products
2(expand)+ 1 more
- (no CPE)
- (no CPE)range: <=0.0.34
Patches
Vulnerability mechanics
References
4- github.com/QwenLM/Qwen-Agent/blob/31a4d36d123688581a9e9744427272b33ce940e0/qwen_agent/tools/simple_doc_parser.pynvd
- github.com/QwenLM/Qwen-Agent/blob/31a4d36d123688581a9e9744427272b33ce940e0/qwen_agent/utils/utils.pynvd
- github.com/QwenLM/Qwen-Agent/issues/912nvd
- www.vulncheck.com/advisories/qwen-agent-arbitrary-file-read-via-caller-supplied-document-pathnvd
News mentions
0No linked articles in our index yet.