CVE-2026-2711Disclosure

LOWCVSS 2.9 · LOW

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A vulnerability has been found in zhutoutoutousan worldquant-miner up to 1.0.9. The impacted element is an unknown function of the file worldquant-miner-master/agent-dify-api/core/helper/ssrf_proxy.py of the component URL Handler. The manipulation of the argument make_request leads to server-side request forgery. The attack can be initiated remotely. The attack's complexity is rated as high. The exploitability is regarded as difficult. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-05-05)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-19: 1Mentions · 2026-05-05: 2PoC Mentioned / Linked · 2026-05-05: 1Technical Details · 2026-05-05: 202-1905-05
Signal classification1 categories
Disclosure
3100.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-02-191
Disclosure1
2026-05-052
Disclosure2
Full discourse3 posts
  • Geng Yang@geng_zast
    Disclosure

    ZAST identified and verified CVE-2026-2711 in worldquant-miner (<=1.0.9). A user-controlled URL reached the server-side fetch flow at /console/api/remote-files. That is enough to turn a convenience feature into SSRF. https://t.co/HuOuDwmLpA

    Post summary

    ZAST announced the discovery of CVE-2026-2711 in worldquant‑miner, identifying a SSRF flaw caused by a user‑controlled URL in the /console/api/remote-files endpoint; a supporting PoC link is included.

    1001089
    48 followersView on X
  • ZAST AI@zast_ai
    Disclosure

    Security note: ZAST identified and verified CVE-2026-2711 in worldquant-miner (<=1.0.9). A user-controlled URL was routed into the backend fetch flow at /console/api/remote-files. That exposed a real SSRF path. https://t.co/KXVbfYg5UC

    Post summary

    ZAST verified CVE-2026-2711 as a Server‑Side Request Forgery in worldquant‑miner (<=1.0.9), revealing that user‑controlled URLs could reach internal resources; no exploit, patch or active‑exploitation details were included.

    1000079
    34 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2711 A vulnerability has been found in zhutoutoutousan worldquant-miner up to 1.0.9. The impacted element is an unknown function of the file worldquant-miner-master/agent-di… https://www.cve.org/CVERecord?id=CVE-2026-2711

    Post summary

    The post announces that CVE‑2026‑2711 has been discovered in worldquant‑miner up to version 1.0.9, but it provides no technical details, PoC, exploit, or patch information.

    00000116
    56.4K followersView on X

Explore more