THREATOPS
THREAT OPSThreat News › Flextype v1.0.0-alpha.3 Server-Side Request Forgery via fetch() in Query API

Flextype v1.0.0-alpha.3 Server-Side Request Forgery via fetch() in Query API

lowfulldisclosurePublished 2026-09-04

<p>Posted by Ron E on Sep 03</p>Description<br /> <br /> Flextype CMS v1.0.0-alpha.3 contains a server-side request forgery (SSRF)<br /> vulnerability in the expression-processing functionality exposed through<br /> the /api/v1/query endpoint. An authenticated remote attacker can supply an<br /> arbitrary URL to the exposed fetch() function, causing the Flextype server<br /> to initiate an outboun

Original source: https://seclists.org/fulldisclosure/2026/Sep/21