CVE-2026-76795: Server-Side Request Forgery in AeternaLabsHQ PullMD
CVE-2026-76795 is a server-side request forgery (SSRF) vulnerability in AeternaLabsHQ PullMD version 3.2.0. It affects an unspecified function within the /api REST API endpoint where manipulation of the 'url' argument allows an attacker to induce the server to make unintended requests. The vulnerability can be exploited remotely without authentication. A fix is available in version 3.3.0.
AI Analysis
Technical Summary
This vulnerability in AeternaLabsHQ PullMD 3.2.0 involves server-side request forgery via the REST API endpoint /api. An attacker can manipulate the 'url' parameter to cause the server to send unauthorized requests to internal or external systems. The vulnerability is remotely exploitable without privileges or user interaction. The issue is resolved by upgrading to version 3.3.0, with the patch identified by commit 96448894cc93ccecb0bdcbf263a9d25390a8455e.
Potential Impact
Successful exploitation allows an attacker to make the vulnerable server perform arbitrary HTTP requests, potentially accessing internal resources or services not otherwise accessible. This can lead to information disclosure or further network-based attacks. The CVSS 4.0 score is 6.9 (medium severity), reflecting the network attack vector, low complexity, and no required privileges or user interaction.
Mitigation Recommendations
Upgrade AeternaLabsHQ PullMD to version 3.3.0, which contains the official fix for this SSRF vulnerability. No other mitigations are indicated or required once the upgrade is applied.
CVE-2026-76795: Server-Side Request Forgery in AeternaLabsHQ PullMD
Description
CVE-2026-76795 is a server-side request forgery (SSRF) vulnerability in AeternaLabsHQ PullMD version 3.2.0. It affects an unspecified function within the /api REST API endpoint where manipulation of the 'url' argument allows an attacker to induce the server to make unintended requests. The vulnerability can be exploited remotely without authentication. A fix is available in version 3.3.0.
CVSS v4.0
Score 6.9medium
Affected software
AeternaLabsHQ
PullMD
pkg:github/aeternalabshq/pullmdcpe:2.3:a:aeternalabshq:pullmd:*:*:*:*:*:*:*:*Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in AeternaLabsHQ PullMD 3.2.0 involves server-side request forgery via the REST API endpoint /api. An attacker can manipulate the 'url' parameter to cause the server to send unauthorized requests to internal or external systems. The vulnerability is remotely exploitable without privileges or user interaction. The issue is resolved by upgrading to version 3.3.0, with the patch identified by commit 96448894cc93ccecb0bdcbf263a9d25390a8455e.
Potential Impact
Successful exploitation allows an attacker to make the vulnerable server perform arbitrary HTTP requests, potentially accessing internal resources or services not otherwise accessible. This can lead to information disclosure or further network-based attacks. The CVSS 4.0 score is 6.9 (medium severity), reflecting the network attack vector, low complexity, and no required privileges or user interaction.
Mitigation Recommendations
Upgrade AeternaLabsHQ PullMD to version 3.3.0, which contains the official fix for this SSRF vulnerability. No other mitigations are indicated or required once the upgrade is applied.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulDB
- Date Reserved
- 2026-08-19T18:22:03.540Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a8656e5acd9273b49eb2fd6
Added to database: 08/20/2026, 01:22:45 UTC
Last enriched: 09/11/2026, 05:34:07 UTC
Last updated: 10/03/2026, 14:46:10 UTC
Views: 89
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.