PT-2026-78420 · Stigmem · Stigmem
CVSS v3.1
6.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Stigmem versions prior to 0.9.0a11
Description
Authenticated users can perform blind Server-Side Request Forgery (SSRF) attacks by specifying internal loopback or private network destinations in the
delivery address parameter during the creation of webhook subscriptions. By triggering matching fact-change events, an attacker can force the server to send HTTP POST requests to internal services and private network endpoints.Recommendations
Update to version 0.9.0a11 or later.
Avoid using the
delivery address parameter to point to internal or loopback addresses until the update is applied.Exploit
Fix
RCE
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Stigmem