8.2
CVE-2026-28677
- EPSS 0.3%
- Veröffentlicht 06.03.2026 04:23:23
- Zuletzt bearbeitet 18.03.2026 12:59:04
- Quelle security-advisories@github.com
- CVE-Watchlists
- Unerledigt
OpenSift: Insufficient URL destination restrictions in ingest flow could enable SSRF-style internal access
OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Prior to version 1.6.3-alpha, the URL ingest pipeline accepted user-controlled remote URLs with incomplete destination restrictions. Although private/local host checks existed, missing restrictions for credentialed URLs, non-standard ports, and cross-host redirects left SSRF-class abuse paths in non-localhost deployments. This issue has been patched in version 1.6.3-alpha.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.3% | 0.212 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 8.2 | 3.9 | 4.2 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
|
CWE-918 Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
https://github.com/OpenSift/OpenSift/pull/67
https://github.com/OpenSift/OpenSift/commit/1126e0a503876056a68a434e19f64158a5a4840b
https://github.com/OpenSift/OpenSift/commit/de99b9c
https://github.com/OpenSift/OpenSift/releases/tag/v1.6.3-alpha
https://github.com/OpenSift/OpenSift/security/advisories/GHSA-5jfc-p787-2mf9