<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 19:14:06 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-241720</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-241720</link>
      <description>EUVD-2026-241720</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-241720</guid>
    </item>
    <item>
      <title>fkie_cve-2024-52588</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-52588</link>
      <description>&lt;p&gt;Strapi is an open-source content management system. Prior to version 4.25.2, inputting a local domain into the Webhooks URL field leads to the application fetching itself, resulting in a server side request forgery (SSRF). This issue has been patched in version 4.25.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Strapi is an open-source content management system. Prior to version 4.25.2, inputting a local domain into the Webhooks URL field leads to the application fetching itself, resulting in a server side request forgery (SSRF). This issue has been patched in version 4.25.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-52588</guid>
    </item>
    <item>
      <title>GHSA-v8wj-f5c7-pvxf — Strapi allows Server-Side Request Forgery in Webhook function</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-v8wj-f5c7-pvxf</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @strapi/admin&lt;/p&gt;
&lt;p&gt;## Description
In Strapi latest version, at function Settings -&amp;gt; Webhooks, the application allows us to input a URL in order to create a Webook connection. However, we can input into this field the local domains such as `localhost`, `127.0.0.1`, `0.0.0.0`,.... in order to make the Application fetching into the internal itself, which causes the vulnerability `Server - Side Request Forgery (SSRF)`.&lt;/p&gt;
&lt;p&gt;## Payloads
- `http://127.0.0.1:80` -&amp;gt; `The Port is not open`
- `http://127.0.0.1:1337` -&amp;gt; `The Port which Strapi is running on`&lt;/p&gt;
&lt;p&gt;## Steps to Reproduce
- First of all, let&amp;#39;s input the URL `http://127.0.0.1:80` into the `URL` field, and click &amp;#34;Save&amp;#34;.&lt;/p&gt;
&lt;p&gt;![CleanShot 2024-06-04 at 22 45 17@2x](https://github.com/strapi/strapi/assets/71650574/7336b817-cb61-41e6-9b3f-87151d8667e9)&lt;/p&gt;
&lt;p&gt;- Next, use the &amp;#34;Trigger&amp;#34; function and use Burp Suite to capture the request / response&lt;/p&gt;
&lt;p&gt;![CleanShot 2024-06-04 at 22 47 50@2x](https://github.com/strapi/strapi/assets/71650574/659f1bbe-6b03-456c-a9c2-5187fca20dd6)&lt;/p&gt;
&lt;p&gt;- The server return `request to http://127.0.0.1/ failed, reason: connect ECONNREFUSED 127.0.0.1:80`, BECAUSE the `Port 80` is not open, since we are running Strapi on `Port 1337`, let&amp;#39;s change the URL we input above into `http://127.0.0.1:1337`&lt;/p&gt;
&lt;p&gt;![CleanShot 2024-06-04 at 22 50 13@2x](https://github.com/strapi/strapi/assets/71650574/a7916c86-1923-49ed-bd43-a70fa00d41e9)&lt;/p&gt;
&lt;p&gt;- Continue to click the &amp;#34;Trigger&amp;#34; function, use Burp to capture the request / response&lt;/p&gt;
&lt;p&gt;![CleanShot 2024-06-04 at 22 53 2…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @strapi/admin&lt;/p&gt;
&lt;p&gt;## Description
In Strapi latest version, at function Settings -&amp;gt; Webhooks, the application allows us to input a URL in order to create a Webook connection. However, we can input into this field the local domains such as `localhost`, `127.0.0.1`, `0.0.0.0`,.... in order to make the Application fetching into the internal itself, which causes the vulnerability `Server - Side Request Forgery (SSRF)`.&lt;/p&gt;
&lt;p&gt;## Payloads
- `http://127.0.0.1:80` -&amp;gt; `The Port is not open`
- `http://127.0.0.1:1337` -&amp;gt; `The Port which Strapi is running on`&lt;/p&gt;
&lt;p&gt;## Steps to Reproduce
- First of all, let&amp;#39;s input the URL `http://127.0.0.1:80` into the `URL` field, and click &amp;#34;Save&amp;#34;.&lt;/p&gt;
&lt;p&gt;![CleanShot 2024-06-04 at 22 45 17@2x](https://github.com/strapi/strapi/assets/71650574/7336b817-cb61-41e6-9b3f-87151d8667e9)&lt;/p&gt;
&lt;p&gt;- Next, use the &amp;#34;Trigger&amp;#34; function and use Burp Suite to capture the request / response&lt;/p&gt;
&lt;p&gt;![CleanShot 2024-06-04 at 22 47 50@2x](https://github.com/strapi/strapi/assets/71650574/659f1bbe-6b03-456c-a9c2-5187fca20dd6)&lt;/p&gt;
&lt;p&gt;- The server return `request to http://127.0.0.1/ failed, reason: connect ECONNREFUSED 127.0.0.1:80`, BECAUSE the `Port 80` is not open, since we are running Strapi on `Port 1337`, let&amp;#39;s change the URL we input above into `http://127.0.0.1:1337`&lt;/p&gt;
&lt;p&gt;![CleanShot 2024-06-04 at 22 50 13@2x](https://github.com/strapi/strapi/assets/71650574/a7916c86-1923-49ed-bd43-a70fa00d41e9)&lt;/p&gt;
&lt;p&gt;- Continue to click the &amp;#34;Trigger&amp;#34; function, use Burp to capture the request / response&lt;/p&gt;
&lt;p&gt;![CleanShot 2024-06-04 at 22 53 2…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-v8wj-f5c7-pvxf</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1154 — Strapi: Schwachstelle ermöglicht Offenlegung von Informationen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1154</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Strapi ausnutzen, um Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Strapi ausnutzen, um Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1154</guid>
    </item>
  </channel>
</rss>
