Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

PinchTab SSRF in /download endpoint allows internal network and file access (CVE-2026-30834)

A Server-Side Request Forgery vulnerability in the /download endpoint of PinchTab, an HTTP server that gives AI agents direct control over Chrome, allowed any user with API access to make the server request arbitrary URLs, including internal network services and local files, and exfiltrate the responses. The issue was patched in version 0.7.7.

Disclosed 7 March 2026 · Record updated 13 September 2026

Impact

Any user with API access could induce the server to fetch arbitrary URLs, including internal network services and local system files, and retrieve the full response content.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-30834