PT-2026-52114 · Appsmith · Appsmith

CVE-2026-55455

·

Published

2026-06-24

·

Updated

2026-06-29

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Appsmith versions prior to 2.1
Description An authenticated user can craft outbound requests that reach loopback-bound services inside the container. This occurs because the outbound HTTP host filter applied by WebClientUtils (used by the REST API and GraphQL datasource plugins) validates hosts against an exact-match string denylist, whereas the comprehensive address-class check for loopback, any-local, link-local, and fc00::/7 is only implemented in the SMTP code path and not the HTTP plugin path.
Recommendations Update to version 2.1.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-APPSMITH-2026-55455
CVE-2026-55455
GHSA-M23H-PVF3-2M7P

Affected Products

Appsmith