Huginn through 2022.08.18 contains a server-side request forgery vulnerability in the fetch_url method of ScenarioImport that allows authenticated… (CVE-2026-63769)
Huginn versions through 2022.08.18 have a server-side request forgery (SSRF) vulnerability in the fetch_url method of ScenarioImport. This flaw allows authenticated users to submit crafted URLs that trigger arbitrary HTTP requests from the server. Exploitation can enable attackers to probe internal network services, enumerate ports using error responses, and access cloud metadata endpoints to obtain sensitive credentials.
AI Analysis
Technical Summary
CVE-2026-63769 describes an SSRF vulnerability in Huginn through version 2022.08.18 within the fetch_url method of ScenarioImport. Authenticated users can exploit this vulnerability by submitting specially crafted URLs, causing the server to make arbitrary HTTP requests. This can be leveraged to scan internal network services, enumerate open ports based on error signatures, and retrieve sensitive data such as cloud metadata credentials. The CVSS 3.1 base score is 7.7, reflecting a high confidentiality impact with no integrity or availability impact. The vulnerability requires low attack complexity and privileges but no user interaction.
Potential Impact
Successful exploitation allows an authenticated attacker to make arbitrary HTTP requests from the server, potentially exposing internal network services and sensitive cloud metadata credentials. This can lead to unauthorized disclosure of confidential information. There is no direct impact on integrity or availability.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no patch links or official fixes are provided, users should monitor vendor communications for updates. Until a fix is available, restrict access to authenticated users and consider limiting network access from the Huginn server to sensitive internal resources and cloud metadata endpoints.
Huginn through 2022.08.18 contains a server-side request forgery vulnerability in the fetch_url method of ScenarioImport that allows authenticated… (CVE-2026-63769)
Description
Huginn versions through 2022.08.18 have a server-side request forgery (SSRF) vulnerability in the fetch_url method of ScenarioImport. This flaw allows authenticated users to submit crafted URLs that trigger arbitrary HTTP requests from the server. Exploitation can enable attackers to probe internal network services, enumerate ports using error responses, and access cloud metadata endpoints to obtain sensitive credentials.
CVSS v3.1
Score 7.7high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-63769 describes an SSRF vulnerability in Huginn through version 2022.08.18 within the fetch_url method of ScenarioImport. Authenticated users can exploit this vulnerability by submitting specially crafted URLs, causing the server to make arbitrary HTTP requests. This can be leveraged to scan internal network services, enumerate open ports based on error signatures, and retrieve sensitive data such as cloud metadata credentials. The CVSS 3.1 base score is 7.7, reflecting a high confidentiality impact with no integrity or availability impact. The vulnerability requires low attack complexity and privileges but no user interaction.
Potential Impact
Successful exploitation allows an authenticated attacker to make arbitrary HTTP requests from the server, potentially exposing internal network services and sensitive cloud metadata credentials. This can lead to unauthorized disclosure of confidential information. There is no direct impact on integrity or availability.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no patch links or official fixes are provided, users should monitor vendor communications for updates. Until a fix is available, restrict access to authenticated users and consider limiting network access from the Huginn server to sensitive internal resources and cloud metadata endpoints.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-9r7r-j892-2c6m
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-63769"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6aa8a1da55bf5e2cf5f3ea89
Added to database: 09/15/2026, 01:39:38 UTC
Last enriched: 09/15/2026, 02:05:40 UTC
Last updated: 09/15/2026, 03:45:22 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.