PT-2026-67876 · Odysseus · Odysseus

·

CVE-2026-70620

·

Published

2026-08-04

·

Updated

2026-08-05

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Odysseus versions prior to commit 87babb5
Description An issue exists where admin-privileged attackers can perform server-side request forgery (SSRF), a technique used to induce the server to make requests to an unintended location. By supplying arbitrary URLs to the embedding endpoint configuration, attackers can probe internal network resources because the system lacks validation for schemes, hosts, IP ranges, or DNS rebinding. This allows the submission of loopback addresses, RFC 1918 ranges (private IP addresses), or link-local addresses through the embedding endpoint API to partially read responses from internal APIs, cloud instance metadata services, and other hosts reachable from the server.
Recommendations Update to the version containing commit 87babb5. Restrict access to the embedding endpoint API to minimize the risk of exploitation.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-70620

Affected Products

Odysseus