Flowintel · Flowintel · CVE-2026-9813
**Name of the Vulnerable Software and Affected Versions**
FlowIntel versions prior to 3.3.1
**Description**
An issue exists in the external reference URL probe functionality within `app/case/task.py`. An attacker can submit an external reference URL to force the application server to issue an HTTP HEAD request to a specified destination. Due to insufficient validation of the URL scheme and resolved destination address, this allows requests to loopback, link-local, private, reserved, or other restricted network resources. This may enable interaction with internal services or cloud metadata endpoints from the server's network context. This is a server-side request forgery (SSRF), which occurs when a server is tricked into making requests to an unintended location.
**Recommendations**
Update to a version later than 3.3.0.