CVE-2026-76900

Source
https://cve.org/CVERecord?id=CVE-2026-76900
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-76900.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-76900
Aliases
  • GHSA-fg6q-pfj7-fghw
Published
2026-09-18T19:56:53Z
Modified
2026-09-26T08:12:04Z
Severity
  • 6.8 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N CVSS Calculator
Summary
CordysCRM: SSRF via Approval Flow Webhook Execution due to Missing SSRF Validation at Runtime
Details

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. In version 1.7.3, ApprovalResourceService.sendWebHook reads WebHookConfig.webHookUrl from stored approval-node configuration and passes it through ApprovalFlowService.updateApprovalPostField to HttpClientUtils without the SSRF validation used by the optional testConnect path. A user with PROCESS_SETTING_ADD can configure an internal URL through POST /approval-flow/add and cause the server to request it when POST /approval-action/approve executes the approval action, enabling cloud metadata access, internal network reconnaissance, and interaction with reachable internal services. This issue is fixed in version 1.7.4.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-918"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/76xxx/CVE-2026-76900.json"
}
References

Affected packages

Git / github.com/1panel-dev/cordyscrm

Affected ranges

Type
GIT
Repo
https://github.com/1panel-dev/cordyscrm
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "= 1.7.3"
        },
        {
            "last_affected": "= 1.7.3"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

= 1.*
= 1.7.3
v1.*
v1.7.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-76900.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "83347479842033023200515311569223989141",
                "232436553629168511290127159040357577274",
                "29794471155429257072471956569261852179",
                "248228210090909829887201180162498735667"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-76900-11799a1f",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/1panel-dev/cordyscrm/commit/e0ae23ebf16faa062204d90a689fe33496541ada",
        "target": {
            "file": "backend/crm/src/main/java/cn/cordys/crm/approval/service/ApprovalResourceService.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "184841500500836189106785970759942065275",
            "length": 225
        },
        "id": "CVE-2026-76900-4f134b57",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/1panel-dev/cordyscrm/commit/e0ae23ebf16faa062204d90a689fe33496541ada",
        "target": {
            "file": "backend/crm/src/main/java/cn/cordys/crm/integration/common/utils/HttpClientUtils.java",
            "function": "doGet"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "260394009816963612633631722237985365919",
            "length": 366
        },
        "id": "CVE-2026-76900-64c77a7d",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/1panel-dev/cordyscrm/commit/e0ae23ebf16faa062204d90a689fe33496541ada",
        "target": {
            "file": "backend/crm/src/main/java/cn/cordys/crm/integration/common/utils/HttpClientUtils.java",
            "function": "doPost"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "127208227295543301795666630741110571930",
            "length": 532
        },
        "id": "CVE-2026-76900-767dd695",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/1panel-dev/cordyscrm/commit/e0ae23ebf16faa062204d90a689fe33496541ada",
        "target": {
            "file": "backend/crm/src/main/java/cn/cordys/crm/approval/service/ApprovalResourceService.java",
            "function": "testConnect"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "297035554684689859976900268137718555754",
                "170303434073081179366561086831023795378",
                "45846805413225389400126786608722788331",
                "137435120986061611741588412491777321525",
                "269534725956125332894559569595136165384",
                "117988473800182647043574568235015816399"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-76900-c81882a1",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/1panel-dev/cordyscrm/commit/83bd0bf7422c0391af6c2f798f62c624a056bf6b",
        "target": {
            "file": "backend/crm/src/main/java/cn/cordys/crm/follow/service/BaseFollowUpService.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "320144658412324829475839133206321393830",
            "length": 1596
        },
        "id": "CVE-2026-76900-c823bc9d",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/1panel-dev/cordyscrm/commit/83bd0bf7422c0391af6c2f798f62c624a056bf6b",
        "target": {
            "file": "backend/crm/src/main/java/cn/cordys/crm/follow/service/BaseFollowUpService.java",
            "function": "checkRecordPermission"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "6676533185429243244927831076574166788",
            "length": 385
        },
        "id": "CVE-2026-76900-ecf3245d",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/1panel-dev/cordyscrm/commit/e0ae23ebf16faa062204d90a689fe33496541ada",
        "target": {
            "file": "backend/crm/src/main/java/cn/cordys/crm/integration/common/utils/HttpClientUtils.java",
            "function": "doRequest"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "185992869145333188575981771805281620251",
                "270995742882537167917212331056064961908",
                "334988732523916493997156563072192428946",
                "210135241255791285182669644070474867023",
                "77794745228821641220698530174996345506",
                "231259006915017793668056681148784841205",
                "239289206940348217040924035931985068000",
                "311903432155823686594707926861754528491",
                "151866465650026841772817467309540664665",
                "137668311219600352713749684355799743177",
                "77491854300973072079983434016115971957",
                "290688300051209560037505197133346705753",
                "25654755642087251397589270072338281551"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-76900-f5dbe414",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/1panel-dev/cordyscrm/commit/e0ae23ebf16faa062204d90a689fe33496541ada",
        "target": {
            "file": "backend/crm/src/main/java/cn/cordys/crm/integration/common/utils/HttpClientUtils.java"
        }
    }
]
vanir_signatures_modified
"2026-09-26T08:12:04Z"