Description
AgentFlow's local web API accepts non-JSON content types on POST /api/runs and POST /api/runs/validate endpoints without enforcing application/json validation, allowing attackers to bypass trust-boundary enforcement on sensitive operations. Attackers can exploit this content-type validation weakness through browser-driven or local cross-origin requests to abuse the localhost API and enable attack chains against the local control plane.
Problem types
CWE-346: Origin Validation Error
Product status
Any version before 1667fa3
Credits
Chia Min Jun Lennon
References
github.com/berabuddies/agentflow/pull/18
github.com/berabuddies/agentflow/pull/18
github.com/berabuddies/agentflow/commit/1667fa3
www.vulncheck.com/...-web-api-content-type-validation-bypass