Tooljet · Tooljet · CVE-2026-55412
**Name of the Vulnerable Software and Affected Versions**
ToolJet versions prior to 3.20.178-lts
**Description**
A Server-Side Request Forgery (SSRF) exists in the RestAPI data source component. The component executes HTTP requests server-side, but the private IP filter only validates the hostname string instead of the resolved IP address. This allows an authenticated user to bypass the filter using DNS names that resolve to the Azure Instance Metadata Service (IMDS) link-local address, enabling the theft of Azure managed identity tokens for the AKS production cluster.
**Recommendations**
Update to version 3.20.178-lts.