PT-2026-52501 · Tooljet · Tooljet

·

CVE-2026-55412

·

Published

2026-06-25

·

Updated

2026-06-25

CVSS v3.1

8.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions ToolJet versions prior to 3.20.178-lts
Description A Server-Side Request Forgery (SSRF) exists in the RestAPI data source component. The component executes HTTP requests server-side, but the private IP filter only validates the hostname string instead of the resolved IP address. This allows an authenticated user to bypass the filter using DNS names that resolve to the Azure Instance Metadata Service (IMDS) link-local address, enabling the theft of Azure managed identity tokens for the AKS production cluster.
Recommendations Update to version 3.20.178-lts.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55412
GHSA-H49F-MHMM-JX4W

Affected Products

Tooljet