CVE-2026-7065

Source
https://cve.org/CVERecord?id=CVE-2026-7065
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-7065.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-7065
Published
2026-04-26T23:00:16.663Z
Modified
2026-07-15T01:49:02.287094076Z
Severity
  • 5.5 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
BidingCC BuildingAI Remote Upload API file-storage.service.ts uploadRemoteFile server-side request forgery
Details

A vulnerability has been found in BidingCC BuildingAI up to 26.0.1. Impacted is the function uploadRemoteFile of the file packages/core/src/modules/upload/services/file-storage.service.ts of the component Remote Upload API. The manipulation of the argument url leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/7xxx/CVE-2026-7065.json",
    "cwe_ids": [
        "CWE-918"
    ],
    "cna_assigner": "VulDB"
}
References

Affected packages

Git / github.com/bidingcc/buildingai

Affected ranges

Type
GIT
Repo
https://github.com/bidingcc/buildingai
Events
Database specific
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "26.0.0"
        },
        {
            "last_affected": "26.0.0"
        },
        {
            "introduced": "26.0.1"
        },
        {
            "last_affected": "26.0.1"
        }
    ]
}

Affected versions

26.*
26.0.0
26.0.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-7065.json"