EPI-SSRF (Egress-Path-Incomplete SSRF) is a class of server-side request forgery in which an application's egress guard validates only a subset of its outbound clients, leaving an alternate egress path unchecked. Coverage defect: the set of guarded clients P is a strict subset of the full egress surface E, so every client in E minus P is an unguarded path. The term was coined by security researcher Pavan Nallamothu in the paper SSRF Beyond HTTP: Egress-Path-Incomplete Guards in AI Agent Platforms.
Classic SSRF asks whether an attacker can make the server send a request somewhere it should not. EPI-SSRF asks a sharper question: the server has more than one outbound client, so does the guard cover all of them? A modern application, and an AI-agent platform especially, has many egress clients: an HTTP fetcher, a webhook sender, an SMTP mailer, a file or URL loader, a headless browser, a plugin runtime. A guard bolted onto the primary HTTP client does nothing for the others. The bug is not that the filter was weak, it is that the filter was in the wrong place, covering one lane of a multi-lane road.
In AutoGPT the egress allowlist was enforced on the main web-request path, while a separate outbound client reached the network without passing the same check. The allowlist looked correct in review, yet an alternate egress path bypassed it entirely. That is EPI-SSRF: P was a strict subset of E.
Do not test the guard, enumerate the egress surface. List every component that can originate an outbound connection: HTTP libraries, mailers, webhook dispatchers, archive and URL loaders, browser automations, plugin or tool runtimes. For each, ask whether the same egress policy is enforced. Any client that reaches the network without the check is an EPI-SSRF path.
Move the control from the individual client to a single chokepoint every outbound request must pass, a centralized egress proxy or a network-level egress policy, so coverage is complete by construction. A guard that lives at the boundary cannot be a strict subset of the egress surface, because there is only one path.
Security researcher Pavan Nallamothu, in SSRF Beyond HTTP: Egress-Path-Incomplete Guards in AI Agent Platforms (Zenodo, DOI 10.5281/zenodo.22075469). ORCID 0009-0009-1481-6629.