Executive brief
OpenAgents is an open-source framework for building and managing AI agents. The HTTP transport layer exposes an unauthenticated endpoint that accepts attacker-controlled URLs and uses them to make HTTP requests, allowing an attacker to access internal services, cloud metadata endpoints, and private networks. This could enable data exfiltration or reconnaissance of internal infrastructure.
Technical details
The vulnerability is a server-side request forgery (SSRF) in the test_default_model function (http.py, lines 4542–4631) of the OpenAgents SDK. The endpoint accepts a JSON POST request containing provider, model_name, api_key, and base_url parameters without authentication checks. When provider is set to 'custom' or 'openai-compatible', the user-supplied base_url is passed directly to SimpleGenericProvider, which instantiates an AsyncOpenAI HTTP client pointing to the attacker-specified URL. No URL validation, IP restrictions, or authentication guards are in place. An attacker can remotely trigger HTTP requests to arbitrary internal endpoints by crafting a POST request to /api/admin/default-model/test with a malicious base_url. The vulnerability affects versions up to 0.8.19 and 0.9.3.post20; the maintainers closed the issue as "not applicable" despite the vulnerable code remaining unchanged.
Affected products
- OpenAgents OpenAgents up to 0.8.19 and 0.9.3.post20
Timeline
- 2026-07-21: disclosed: Issue #566 opened on GitHub
- 2026-09-07: advisory: CVE-2026-86237 published