CVE-2026-87821
Lara Dashboard through 1.3.1 contains a server-side request forgery vulnerability in the POST /api/admin/builder/markdown/fetch endpoint that allows any authenticated user to fetch arbitrary URLs and read the response body. Attackers can read internal HTTP services and cloud metadata including IAM credentials by supplying malicious URLs without host validation or redirect restrictions.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.1
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
- CWE
- CWE-918
- Published
- 2026-09-09
- Last modified
- 2026-09-09
Affected products
- laradashboard laradashboard
Weakness type
Related vulnerabilities
- CVE-2026-88896 — EspoCRM before 10.0.4 SSRF via IPv6 Transition Address Bypass
- CVE-2026-88892 — OpenPanel SSRF via Unguarded Importer File URL Fetch
- CVE-2026-88001 — Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targets
- CVE-2026-87999 — Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetch
- CVE-2026-87996 — Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loader
- CVE-2026-19233 — CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthorized...
- CVE-2026-86771 — Snipe-IT before 8.7.0 Server-Side Request Forgery via employee_num
- CVE-2026-79635 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...