PT-2026-34564 · Squidex · Squidex

Published

2026-04-22

·

Updated

2026-04-23

·

CVE-2026-41171

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Squidex versions prior to 7.23.0
Description An issue exists in the scripting engine functions, such as getJSON() and request(), due to missing Server-Side Request Forgery (SSRF) protection on the Jint HTTP client. SSRF is a flaw that allows an attacker to induce the server-side application to make requests to an unintended location. An authenticated user with low privileges, such as schema editing permissions, can force the server to make arbitrary outbound HTTP requests to internal endpoints or attacker-controlled servers. This can lead to unauthorized access to internal services and cloud metadata endpoints, such as the Instance Metadata Service (IMDS), potentially resulting in credential exposure and lateral movement within the network.
Recommendations Update to version 7.23.0.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41171

Affected Products

Squidex