CVE-2026-46391
HIGHHAX open-apis: Credential Theft via Server-Side Request Forgery (SSRF) in open-apis
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2026-46391. PoCs published by bradyjmcl.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2026-46391, which leverages an SSRF vulnerability in the `cacheAddress` endpoint of `@haxtheweb/open-apis` to expose service account credentials. The exploit sets up a listener to capture the credentials sent via an Authorization header in the SSRF callback.
Description
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Starting in version 9.0.1 and prior to version 26.0.0 of @haxtheweb/open-apis, multiple functions conduct substring-only matching to validate hostnames to which basic authorization should be sent. An attacker can append the matched substrings to an attacker-controlled endpoint and capture authentication. Version 26.0.0 fixes the issue.
Exploits (1)
This repository contains a functional exploit for CVE-2026-46391, which leverages an SSRF vulnerability in the `cacheAddress` endpoint of `@haxtheweb/open-apis` to expose service account credentials. The exploit sets up a listener to capture the credentials sent via an Authorization header in the SSRF callback.
References (1)
Scores
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X