PT-2026-95100 · Glean · Glean
CVSS v3.1
7.7
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Glean versions prior to 0.2.6
Description
An issue exists where the application fails to perform network-level validation on URLs provided in RSS feeds. When a user submits a
feed url via the 'POST /api/feeds/discover' endpoint, the system processes it through the discover feed(feed url) function and FeedService.create subscription(), eventually triggering the fetch feed task. This task utilizes fetch feed(feed.url) and parse feed(), which assign links to ParsedEntry.url. Subsequently, fetch and extract fulltext(parsed entry.url) is called without proper validation in backend/packages/rss/glean rss/extractor.py and backend/apps/worker/glean worker/tasks/feed fetcher.py. This allows a malicious feed to trigger a non-blind server-side request forgery (SSRF), enabling the server to request private, loopback, link-local, or cloud-metadata resources. The resulting response is stored in Entry.content and can be accessed via the 'GET /api/entries/{id}' endpoint, potentially exposing internal services, ports, configurations, or cloud metadata access tokens.Recommendations
Update to version 0.2.6.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Glean