PT-2026-93813 · Git+1 · Mlrun
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
MLRun versions prior to 1.11.0
Description
An issue exists in the WebhookNotification handler that allows authenticated users to perform server-side request forgery (SSRF). By updating a run with a malicious webhook notification, an attacker can force the API server to send arbitrary HTTP requests to internal addresses when the run reaches a terminal state. This can be used to target internal services, Kubernetes APIs, or cloud metadata endpoints from within the cluster.
Recommendations
Update to a version later than 1.11.0.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mlrun