Junglewise Threat Intelligence

CVE-2026-82275: QwenLM Qwen-Agent path traversal in document parser

CVE-2026-82275 · Severity: high · CVSS 7.5 · Published 2026-08-28

Executive brief

Qwen-Agent is an AI agent framework and application platform built on Qwen LLM. The vulnerability allows attackers to read arbitrary files from the server by exploiting a path traversal flaw in the document parser through an unauthenticated web interface, potentially exposing sensitive configuration files, credentials, and proprietary data.

Technical details

The vulnerability is a path traversal flaw in the document parser component (simple_doc_parser.py) that fails to properly validate and restrict file paths supplied by users. Attackers can supply absolute file paths directly to the unauthenticated Gradio interface, which processes document uploads without adequate input validation. The parser does not sanitize or restrict file access to intended directories, allowing attackers to read arbitrary files accessible by the server process. No authentication is required to exploit this vulnerability as the Gradio interface is publicly exposed. The issue affects Qwen-Agent versions through 0.0.34.

Affected products

  • QwenLM Qwen-Agent through 0.0.34

Timeline

  • 2026-08-28: disclosed

References