Server-Side Request Forgery Vulnerability in Swarms by Kyegomez
CVE-2026-67346
7.7HIGH
What is CVE-2026-67346?
Swarms version 6.8.1 contains a vulnerability in the _is_safe_url function, which inadequately validates hostnames during DNS resolution. This flaw allows attackers to exploit user-provided image or audio URLs that resolve to private, loopback, or metadata addresses. Consequently, this enables unauthorized access to internal services, posing significant security risks including the potential exfiltration of sensitive credentials.
Affected Version(s)
swarms 0 <= 6.8.1
swarms 8b0fc9e4645603ad94d5fcf4da86e3b9c71f4743
