Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Nightingale SSRF vulnerability in http_fetch AI-agent tool

Nightingale (n9e) contains a server-side request forgery vulnerability in the isPublicIP function that fails to properly unwrap certain IPv6 address formats, allowing attackers to bypass SSRF guards and reach internal services or metadata endpoints.

Disclosed 27 August 2026 · Record updated 13 September 2026

Impact

Attackers able to supply URLs to the http_fetch tool can bypass SSRF protection to reach internal or metadata services on dual-stack or NAT64-enabled hosts.

Our coverage

No articles linked to this incident yet.

Sources

  1. github.comhttps://github.com/advisories/GHSA-wc5f-hgwx-ffx9