agentos-taskweaver@0.1.0 vulnerabilities

A code-first agent framework for seamlessly planning and executing data analytics tasks

Direct Vulnerabilities

Known vulnerabilities in the agentos-taskweaver package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • M
Server-side Request Forgery (SSRF)

agentos-taskweaver is an A code-first agent framework for seamlessly planning and executing data analytics tasks

Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) via the network configuration process. An attacker can access local services running on the host system by sending crafted requests from within a container environment. This is only exploitable if the application is running in a Docker, Podman, or Containerd container on MacOS or Windows hosts, where special internal hostnames are available to the container.

How to fix Server-side Request Forgery (SSRF)?

A fix was pushed into the master branch but not yet published.

[0,)