Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-85650

Опубликовано: 04 сент. 2026
Источник: nvd
CVSS3: 5.4
EPSS Низкий

Описание

Trigger.dev before 4.5.2 contains a server-side request forgery vulnerability in webhook alert channel delivery URLs that are fetched without validation or SSRF protection. Authenticated users with organization membership can create alert channels with URLs targeting internal services and metadata endpoints, allowing the server to issue POST requests to restricted resources.

EPSS

Процентиль: 24%
0.00313
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 5.4
github
14 дней назад

Trigger.dev before 4.5.2 contains a server-side request forgery vulnerability in webhook alert channel delivery URLs that are fetched without validation or SSRF protection. Authenticated users with organization membership can create alert channels with URLs targeting internal services and metadata endpoints, allowing the server to issue POST requests to restricted resources.

EPSS

Процентиль: 24%
0.00313
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-918