Tugtainer · Tugtainer · CVE-2026-62308
**Name of the Vulnerable Software and Affected Versions**
Tugtainer versions prior to 1.30.6
**Description**
An authenticated user can trigger the backend server to send outbound HTTP requests to arbitrary user-supplied URLs. This occurs via the '/settings/test notification' endpoint, which accepts a `urls` field and passes it to Apprise without restricting protocols, hostnames, localhost addresses, private IP ranges, or cloud metadata addresses. This flaw enables an authenticated blind server-side request forgery (SSRF), a condition where an attacker induces the server to make requests to an unintended location.
**Recommendations**
Update to version 1.30.6.