VYPR
High severityNVD Advisory· Published Apr 22, 2026· Updated Apr 24, 2026

CVE-2026-41171

CVE-2026-41171

Description

Squidex is an open source headless content management system and content management hub. Versions prior to 7.23.0 have a Server-Side Request Forgery (SSRF) vulnerability due to missing SSRF protection on the Jint HTTP client used by scripting engine functions (getJSON, request, etc.). An authenticated user with low privileges (e.g., schema editing permissions) can force the server to make arbitrary outbound HTTP requests to attacker-controlled or internal endpoints. This allows access to internal services and cloud metadata endpoints (e.g., IMDS), potentially leading to credential exposure and lateral movement. Version 7.23.0 contains a fix.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Squidex/Squidexreferences2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: <7.23.0

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.