PT-2026-32027 · Chartbrew+1 · Chartbrew+1

Razvanilin

·

Published

2026-04-10

·

Updated

2026-04-10

·

CVE-2026-30232

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Chartbrew versions prior to 4.8.5
Description Chartbrew is a web application that connects to databases and APIs to create charts. Before version 4.8.5, authenticated users could create API data connections with arbitrary URLs. The server fetches these URLs using the request-promise library without validating IP addresses, which allows for Server-Side Request Forgery (SSRF) attacks against internal networks and cloud metadata endpoints.
Recommendations Update to version 4.8.5 or later.

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2026-30232

Affected Products

Chartbrew
Request-Promise