PT-2026-21330 · Openshift · Openshift

Mdavistffhrtporg

·

Published

2026-02-20

·

Updated

2026-02-21

·

CVE-2026-27170

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenSift versions 1.1.2-alpha and below
Description OpenSift is an AI study tool that uses semantic search and generative AI to process large datasets. The software’s URL ingest feature in versions 1.1.2-alpha and earlier exhibits overly permissive server-side fetch behavior, potentially allowing requests to unsafe targets. This can lead to probing of private or local network resources from the OpenSift host process when processing attacker-controlled URLs. The API endpoint responsible for URL ingestion is susceptible to this issue. The vulnerable parameter is the URL itself, which is used in a server-side fetch operation.
Recommendations Update to version 1.1.3-alpha or later. If using trusted local-only exceptions, use OPENSIFT ALLOW PRIVATE URLS=true with caution.

Exploit

Fix

RCE

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-27170
GHSA-3W2R-HJ5P-H6PP

Affected Products

Openshift