CVE-2025-59956

MEDIUM

AgentAPI <0.3.3 - SSRF

Title source: llm
STIX 2.1

Description

AgentAPI is an HTTP API for Claude Code, Goose, Aider, Gemini, Amp, and Codex. Versions 0.3.3 and below are susceptible to a client-side DNS rebinding attack when hosted over plain HTTP on localhost. An attacker can gain access to the /messages endpoint served by the Agent API. This allows for the unauthorized exfiltration of sensitive user data, specifically local message history, which can include secret keys, file system contents, and intellectual property the user was working on locally. This issue is fixed in version 0.4.0.

Scores

CVSS v3 6.5
EPSS 0.0007
EPSS Percentile 21.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-350 CWE-290
Status published
Products (2)
coder/agentapi < 0.4.0
coder/agentapi 0 - 0.4.0Go
Published Sep 30, 2025
Tracked Since Feb 18, 2026