Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Sha1Cybr

#16167of 56,330
17.7Total CVSS
Vulnerabilities · 2
High
1
Critical
1
PT-2026-52501
8.3
2026-06-25
Tooljet · Tooljet · CVE-2026-55412
**Name of the Vulnerable Software and Affected Versions** ToolJet versions prior to 3.20.178-lts **Description** A Server-Side Request Forgery (SSRF) exists in the RestAPI data source component. The component executes HTTP requests server-side, but the private IP filter only validates the hostname string instead of the resolved IP address. This allows an authenticated user to bypass the filter using DNS names that resolve to the Azure Instance Metadata Service (IMDS) link-local address, enabling the theft of Azure managed identity tokens for the AKS production cluster. **Recommendations** Update to version 3.20.178-lts.
PT-2026-52502
9.4
2026-06-25
Tooljet · Tooljet · CVE-2026-55413
**Name of the Vulnerable Software and Affected Versions** ToolJet versions prior to 3.20.178-lts **Description** An issue exists where an authenticated user with a builder role can overwrite a globally-shared marketplace plugin with arbitrary JavaScript. This code executes server-side with full Node.js access, including `require` and `process`, whenever any user on the instance triggers a query using the affected plugin. This leads to Remote Code Execution (RCE) and a supply-chain compromise of the entire deployment. **Recommendations** Update to version 3.20.178-lts.