PT-2026-103471 · Tugtainer · Tugtainer

·

CVE-2026-62308

·

Published

2026-09-30

·

Updated

2026-09-30

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions Tugtainer versions prior to 1.30.6
Description An authenticated user can trigger the backend server to send outbound HTTP requests to arbitrary user-supplied URLs. This occurs via the '/settings/test notification' endpoint, which accepts a urls field and passes it to Apprise without restricting protocols, hostnames, localhost addresses, private IP ranges, or cloud metadata addresses. This flaw enables an authenticated blind server-side request forgery (SSRF), a condition where an attacker induces the server to make requests to an unintended location.
Recommendations Update to version 1.30.6.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-62308
GHSA-C2H5-PPV9-7VRQ

Affected Products

Tugtainer