PT-2026-81483 · Unknown · Dradis Community Edition
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Dradis Community Edition (affected versions not specified)
Description
An authorization bypass exists in the
ProvidersController and AgentsController because the admin required before action depends on the defined?(Dradis::Pro) constant, which is not defined in the Community Edition. This allows any authenticated non-admin user to create an AI provider pointing to an arbitrary HTTP/HTTPS address, including internal or link-local hosts. By reassigning the built-in Roslin agent to this provider, an attacker can trigger a server-side request forgery (SSRF), where the server sends a request to the attacker-supplied URL. For non-2xx responses, the response body is reflected to the attacker's browser via ActionCable/Turbo Stream error messages, allowing the SSRF to be readable.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dradis Community Edition