PT-2026-86393 · Rowboat · Rowboat
CVSS v3.1
5.0
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Rowboat versions prior to 0.9.2
Description
Authenticated users can configure arbitrary destinations because the software fails to validate custom MCP server and webhook URLs. This allows attackers to point these URLs at internal services and cloud metadata endpoints to perform server-side request forgery (SSRF)—a technique where the server is coerced into making requests to an unintended location—and enumerate internal network topology.
Recommendations
Update Rowboat to version 0.9.2 or later.
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rowboat