PT-2026-52543 · Unknown · Huly Platform

George Chen

·

Published

2026-06-25

·

Updated

2026-06-25

·

CVE-2026-56769

CVSS v3.1

8.5

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Huly Platform versions prior to 0.7.423
Description An authenticated server-side request forgery (SSRF) occurs in the /import endpoint of the front pod. This allows workspace users to initiate arbitrary server requests by providing malicious URLs. This can be used to access internal services, exfiltrate responses, and replay credentials against backend systems. SSRF is a flaw where a server is tricked into making requests to an unintended location.
Recommendations Update Huly Platform to version 0.7.423 or later. As a temporary mitigation, restrict access to the /import endpoint.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56769

Affected Products

Huly Platform