Nightingale SSRF vulnerability in http_fetch AI-agent tool
Nightingale (n9e) contains a server-side request forgery vulnerability in the isPublicIP function that fails to properly unwrap certain IPv6 address formats, allowing attackers to bypass SSRF guards and reach internal services or metadata endpoints.
Disclosed 27 August 2026 · Record updated 13 September 2026
Impact
Attackers able to supply URLs to the http_fetch tool can bypass SSRF protection to reach internal or metadata services on dual-stack or NAT64-enabled hosts.
Our coverage
No articles linked to this incident yet.
Sources
- github.comhttps://github.com/advisories/GHSA-wc5f-hgwx-ffx9
