PT-2026-103632 · Decolua · Decolua

·

CVE-2026-103530

·

Published

2026-09-30

·

Updated

2026-10-01

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions decolua 9Router versions prior to 0.5.56
Description A server-side request forgery (SSRF) issue exists in the Search Endpoint component. This occurs when the fetch() function within the src/shared/utils/ssrfGuard.js file does not properly handle the provider options.baseUrl variable, allowing a remote attacker to manipulate it to trigger unauthorized requests from the server.
Recommendations Apply a patch to resolve the issue in versions prior to 0.5.56.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-103530

Affected Products

Decolua