PT-2026-52543 · Unknown · Huly Platform
George Chen
·
Published
2026-06-25
·
Updated
2026-06-25
·
CVE-2026-56769
CVSS v3.1
8.5
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Huly Platform versions prior to 0.7.423
Description
An authenticated server-side request forgery (SSRF) occurs in the
/import endpoint of the front pod. This allows workspace users to initiate arbitrary server requests by providing malicious URLs. This can be used to access internal services, exfiltrate responses, and replay credentials against backend systems. SSRF is a flaw where a server is tricked into making requests to an unintended location.Recommendations
Update Huly Platform to version 0.7.423 or later.
As a temporary mitigation, restrict access to the
/import endpoint.Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Huly Platform