GHSA-5g86-85rp-f9hx
LOWCVE-2026-48051Papra's webhook delivery system contains an SSRF protection bypass that allows any authenticated organisation member to cause the server to make HTTP requests to internal addresses — loopback, link-local, and RFC-1918 ranges. The SSRF protection validates the registered webhook URL but ignores redirect destinations. The HTTP client (ofetch) follows 3xx responses automatically, and the redirect tar
- Affected
- >=0, <0.3.3, < 0.3.3
- Fixed in
- 0.3.3
- Weakness
- CWE-918
- Published
- 2026-06-10
- Source
- osv