A vulnerability, which was classified as problematic, was found in heshengtao super-agent-party up to 0.4.1. This affects the function
get_file_content of the file server.py of the component execute_tool_manually Endpoint. The manipulation of the argument tool_name/tool_params results in information disclosure.
This vulnerability is reported as CVE-2026-18974. The attack can be launched remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.