Agent SSRF to cloud metadata / file inclusion via unvalidated fetch URL - ATR-2026-00568 (7ccc3f00-0294-5fa1-b01b-03715630cca9)
An agent tool fetches an attacker-controlled URL with no scheme allowlist or private-network block, letting it reach cloud-metadata endpoints (credential theft), local files via file://, or SSRF-only schemes (gopher/dict). Detects those unambiguous internal targets. Generalizes across CVE-2026-40150/40160 (PraisonAIAgents), CVE-2026-7817 (pgAdmin), CVE-2026-45401 (Open WebUI).