CVE-2026-63769

Source
https://cve.org/CVERecord?id=CVE-2026-63769
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63769.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-63769
Published
2026-07-20T19:05:41.298Z
Modified
2026-07-21T03:47:30.851333402Z
Severity
  • 6.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N CVSS Calculator
Summary
Huginn 2022.08.18 SSRF via ScenarioImport fetch_url Method
Details

Huginn through 2022.08.18 contains a server-side request forgery vulnerability in the fetch_url method of ScenarioImport that allows authenticated users to make arbitrary HTTP requests by submitting crafted URLs. Attackers can probe internal network services, enumerate ports via error signatures, and access cloud metadata endpoints to retrieve sensitive credentials.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63769.json",
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-918"
    ]
}
References

Affected packages

Git / github.com/huginn/huginn

Affected ranges

Type
GIT
Repo
https://github.com/huginn/huginn
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "2022.08.18"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

v2022.*
v2022.01.04
v2022.08.18

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63769.json"