CVE-2026-46391

HIGH

HAX open-apis: Credential Theft via Server-Side Request Forgery (SSRF) in open-apis

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-46391. PoCs published by bradyjmcl.

AI-analyzed exploit summary This repository contains a functional exploit for CVE-2026-46391, which leverages an SSRF vulnerability in the `cacheAddress` endpoint of `@haxtheweb/open-apis` to expose service account credentials. The exploit sets up a listener to capture the credentials sent via an Authorization header in the SSRF callback.

Description

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Starting in version 9.0.1 and prior to version 26.0.0 of @haxtheweb/open-apis, multiple functions conduct substring-only matching to validate hostnames to which basic authorization should be sent. An attacker can append the matched substrings to an attacker-controlled endpoint and capture authentication. Version 26.0.0 fixes the issue.

Exploits (1)

github WORKING POC
by bradyjmcl · gopoc
https://github.com/bradyjmcl/cve-2026-46391

This repository contains a functional exploit for CVE-2026-46391, which leverages an SSRF vulnerability in the `cacheAddress` endpoint of `@haxtheweb/open-apis` to expose service account credentials. The exploit sets up a listener to capture the credentials sent via an Authorization header in the SSRF callback.

Classification
Working Poc 100%
Attack Type
Ssrf
Complexity
Moderate
Reliability
Reliable
Target: @haxtheweb/open-apis
No auth needed
Prerequisites: network access to the target server · ability to receive callbacks on a specified listener
mistral-large-3 · analyzed Jun 20, 2026 Full analysis →

References (1)

Core 1
Core References

Scores

CVSS v4 8.7
EPSS 0.0046
EPSS Percentile 37.4%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-183 CWE-918
Status published
Products (2)
haxtheweb/@haxtheweb/open-apis >= 9.0.1, < 26.0.0
haxtheweb/open-apis 0 - 26.0.0npm
Published Jun 05, 2026
Tracked Since Jun 06, 2026