Flowci · Flow-Core-X · CVE-2026-4215
**Name of the Vulnerable Software and Affected Versions**
FlowCI flow-core-x versions through 1.23.01
**Description**
A security flaw exists in FlowCI flow-core-x. The issue resides in the `Save` function within the `core/src/main/java/com/flowci/core/config/service/ConfigServiceImpl.java` file of the SMTP Host Handler component. This manipulation can lead to server-side request forgery, and the attack can be initiated remotely. The exploit is publicly available. The vendor was notified but did not respond.
**Recommendations**
Versions prior to 1.23.01 are affected. At the moment, there is no information about a newer version that contains a fix for this vulnerability.