Appsmithorg · Appsmith · CVE-2026-5418
Name of the Vulnerable Software and Affected Versions
appsmithorg appsmith versions up to 1.97
Description
A server-side request forgery exists due to manipulation of the `computeDisallowedHosts` function within the file `app/server/appsmith-interfaces/src/main/java/com/appsmith/util/WebClientUtils.java` of the Dashboard component. This issue can be exploited remotely.
Recommendations
Upgrade to version 1.99 or later.