PT-2026-69450 · Unknown · Automatisch

·

CVE-2026-72566

·

Published

2026-08-10

·

Updated

2026-08-29

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions automatisch versions prior to commit 41f3c56
Description A server-side request forgery (SSRF) issue exists where a low-privileged authenticated user with 'manage Flow' permission can force the server to fetch arbitrary URLs and retrieve the full response body. This occurs because the handler in packages/backend/src/apps/http-request/actions/custom-request/index.js passes the user-supplied URL directly to the HTTP client without SSRF controls, potentially allowing access to internal services and metadata endpoints via the HTTP Request app's Custom Request action.
Recommendations Update to a version that includes commit 41f3c56 or later. Restrict the use of the Custom Request action within the HTTP Request app for users with 'manage Flow' permissions until the update is applied.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-72566

Affected Products

Automatisch