CVE-2026-4308Disclosure

LOWCVSS 2.1 · LOW

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

A weakness has been identified in frdel/agent0ai agent-zero 0.9.7. This affects the function handle_pdf_document of the file python/helpers/document_query.py. This manipulation causes server-side request forgery. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-03-17); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-03-17: 3Mentions · 2026-03-18: 1Active Exploitation · 2026-03-18: 1Technical Details · 2026-03-17: 203-1703-18
Signal classification3 categories
Disclosure
250.0%
General
125.0%
Active Exploitation
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-173
Disclosure2General1
2026-03-181
Active Exploitation1
Full discourse4 posts
  • VulDB 🛡@vuldb
    Active Exploitation

    Attention, elevated activities detected targeting frdel and agent0ai agent-zero (CVE-2026-4308) https://vuldb.com/?ctiid.351338

    Post summary

    The message reports that elevated activity has been detected targeting CVE-2026-4308, indicating potential active exploitation in the wild, but offers no detailed technical or mitigation information.

    0000094
    2.1K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4308 - frdel/agent0ai agent-zero document_query.py handle_pdf_document server-side request forgery Intel Report: https://ift.tt/zvosXO4

    Post summary

    A new server‑side request forgery vulnerability (CVE‑2026‑4308) in the frdel/agent0ai agent‑zero project has been identified, with a link to an Intel report for further details.

    0000070
    336 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4308 Server-Side Request Forgery in Agent-Zero 0.9.7 via PDF Document Handling https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4308

    Post summary

    CVE‑2026‑4308 is disclosed as an SSRF flaw in Agent‑Zero 0.9.7 triggered by PDF handling, with no PoC, exploit, or patch information provided.

    0000076
    4.0K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-4308 📊 Severity: 6.3 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-4308 #CVE-2026-4308 #CVE #Medium  #CyberSecurity #InfoSec https://t.co/qPO6AXQw26

    Post summary

    The tweet announces the CVE with minimal metadata (severity, risk, product unspecified) but provides no technical, exploit, or mitigation details.

    0000036
    101 followersView on X

Explore more