VYPR
Unrated severityNVD Advisory· Published Jul 20, 2026· Updated Jul 21, 2026

Huginn 2022.08.18 SSRF via ScenarioImport fetch_url Method

CVE-2026-63769

Description

Huginn through 2022.08.18 contains a server-side request forgery vulnerability in the fetch_url method of ScenarioImport that allows authenticated users to make arbitrary HTTP requests by submitting crafted URLs. Attackers can probe internal network services, enumerate ports via error signatures, and access cloud metadata endpoints to retrieve sensitive credentials.

Affected products

1

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.