CVE-2026-63769

HIGH

Huginn 2022.08.18 SSRF via ScenarioImport fetch_url Method

Title source: cna
STIX 2.1

Description

Huginn through 2022.08.18 contains a server-side request forgery vulnerability in the fetch_url method of ScenarioImport that allows authenticated users to make arbitrary HTTP requests by submitting crafted URLs. Attackers can probe internal network services, enumerate ports via error signatures, and access cloud metadata endpoints to retrieve sensitive credentials.

References (3)

Core 3
Core References
Exploit technical-description exploit issue-tracking
Researcher Disclosure
https://github.com/huginn/huginn/issues/3679
Issue Tracking issue-tracking patch
Pull Request
https://github.com/huginn/huginn/pull/3684

Scores

CVSS v3 7.7
EPSS 0.0023
EPSS Percentile 14.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-918
Status published
Products (1)
huginn/huginn < 2022.08.18
Published Jul 20, 2026
Tracked Since Jul 21, 2026