VulnWatch VulnWatch
← Back to dashboard
High nvd · CVE-2026-82275

CVE-2026-82275: Qwen-Agent through 0.0.34 contains a path traversal vulnerability in the document parser that fails to restrict file acc

Published Aug 28, 2026 CVSS 8.7

Qwen-Agent through 0.0.34 contains a path traversal vulnerability in the document parser that fails to restrict file access to intended directories. Attackers can supply absolute file paths to the unauthenticated Gradio interface to read arbitrary files accessible by the server process.

Affected AI Products

qwen
Get the weekly digest. Every Monday: top AI security stories of the week. Free.