PT-2026-52501 · Tooljet · Tooljet
CVSS v3.1
8.3
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
ToolJet versions prior to 3.20.178-lts
Description
A Server-Side Request Forgery (SSRF) exists in the RestAPI data source component. The component executes HTTP requests server-side, but the private IP filter only validates the hostname string instead of the resolved IP address. This allows an authenticated user to bypass the filter using DNS names that resolve to the Azure Instance Metadata Service (IMDS) link-local address, enabling the theft of Azure managed identity tokens for the AKS production cluster.
Recommendations
Update to version 3.20.178-lts.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tooljet