Noncegeek · Dim-Sum-App · CVE-2026-94038
**Name of the Vulnerable Software and Affected Versions**
NonceGeek dim-sum-app (affected versions not specified)
**Description**
An issue in the Deno Backend component within the file `deno/main.tsx` allows for server-side request forgery, a technique where an attacker induces the server to make requests to an unintended location. This occurs through the manipulation of the `supabase url` argument in the `textSearchV2Handler()` function. The attack can be executed remotely.
**Recommendations**
Apply patch 8389032e5d52c28c4855c6126ca7d0eae8af346a.
As a temporary workaround, restrict the use of the `supabase url` argument in the `textSearchV2Handler()` function.