PT-2026-32027 · Unknown+1 · Request-Promise+1

·

CVE-2026-30232

·

Published

2026-04-10

·

Updated

2026-04-10

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Chartbrew versions prior to 4.8.5
Description Chartbrew is a web application that connects to databases and APIs to create charts. Before version 4.8.5, authenticated users could create API data connections with arbitrary URLs. The server fetches these URLs using the request-promise library without validating IP addresses, which allows for Server-Side Request Forgery (SSRF) attacks against internal networks and cloud metadata endpoints.
Recommendations Update to version 4.8.5 or later.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-30232
GHSA-P4RG-967R-W4CV

Affected Products

Chartbrew
Request-Promise