PT-2026-21330 · Openshift · Openshift

Mdavistffhrtporg

·

Publicado

2026-02-20

·

Atualizado

2026-02-21

·

CVE-2026-27170

CVSS v3.1

7.1

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenSift versions 1.1.2-alpha and below
Description OpenSift is an AI study tool that uses semantic search and generative AI to process large datasets. The software’s URL ingest feature in versions 1.1.2-alpha and earlier exhibits overly permissive server-side fetch behavior, potentially allowing requests to unsafe targets. This can lead to probing of private or local network resources from the OpenSift host process when processing attacker-controlled URLs. The API endpoint responsible for URL ingestion is susceptible to this issue. The vulnerable parameter is the URL itself, which is used in a server-side fetch operation.
Recommendations Update to version 1.1.3-alpha or later. If using trusted local-only exceptions, use OPENSIFT ALLOW PRIVATE URLS=true with caution.

Exploit

Correção

RCE

SSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-27170
GHSA-3W2R-HJ5P-H6PP

Produtos afetados

Openshift