Critical

SSRF via Agent URL Fetch Instruction

An attacker sends an AI agent a request instructing it to fetch or retrieve content from an internal or restricted network address, such as a cloud metadata endpoint or a private IP. If the agent has a web-fetch tool and no restriction on target hosts, it can be turned into a proxy that reaches services never meant to be exposed.

How the attack works

The attacker crafts a prompt asking the agent to 'fetch', 'retrieve', or 'check' a URL pointing at an internal-looking target: a cloud metadata IP like 169.254.169.254, localhost/127.0.0.1, an RFC-1918 private address, or a hostname that looks internal. The agent's web-fetch tool executes the request using the server's own network position, not the attacker's. If the target is a cloud metadata service, the response can contain credentials or instance data; if it's a loopback admin panel or internal service, the agent may return configuration data or trigger actions on it. The attacker never needs direct network access — the agent does the work for them.

Netzilo detection

Netzilo reports this behaviour when it is observed.

Signature ID
34f4fe45-cf5a-494b-bf4b-405480fa3158
Severity
Critical

Why it matters

Successful SSRF through an agent can leak cloud credentials, expose internal admin interfaces, or let an outsider probe and interact with internal-only services, all without ever breaching the network perimeter directly.

What you can do

  • Restrict any agent web-fetch tool to an allowlist of external domains and explicitly block cloud metadata IPs, loopback, and RFC-1918 ranges.
  • Require the fetch tool to run through an egress proxy that enforces destination restrictions independent of the agent's own logic.
  • Log and review all URLs an agent's fetch tool is instructed to retrieve, flagging any private or metadata-range addresses.
  • Treat internal developer tooling that fetches internal URLs as a separate, explicitly authorized workflow, not something exposed through a general-purpose agent.

Known benign look-alikes

  • Network troubleshooting discussions mentioning private IP ranges without fetch instructions
  • Educational content about SSRF attacks with sanitised examples
  • Internal developer tooling that legitimately fetches internal URLs with operator authorization

References

Related threats