PT-2026-32027 · Chartbrew+1 · Chartbrew+1
Razvanilin
·
Published
2026-04-10
·
Updated
2026-04-10
·
CVE-2026-30232
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Chartbrew versions prior to 4.8.5
Description
Chartbrew is a web application that connects to databases and APIs to create charts. Before version 4.8.5, authenticated users could create API data connections with arbitrary URLs. The server fetches these URLs using the
request-promise library without validating IP addresses, which allows for Server-Side Request Forgery (SSRF) attacks against internal networks and cloud metadata endpoints.Recommendations
Update to version 4.8.5 or later.
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Chartbrew
Request-Promise