![]() |
|
HackerOne Disclosed Reports - 2025-12-22 - Printable Version +- Dark C0d3rs (https://darkcoders.wiki) +-- Forum: Exploit Log (https://darkcoders.wiki/Forum-Exploit-Log) +--- Forum: Research Papers/Vulnerability reports (https://darkcoders.wiki/Forum-Research-Papers-Vulnerability-reports) +--- Thread: HackerOne Disclosed Reports - 2025-12-22 (/Thread-HackerOne-Disclosed-Reports-2025-12-22) |
HackerOne disclosed reports - 2025-12-22 - hashXploiter - 12-23-2025
Medium
resolved Link unfurling calls out to arbitrary URLs and the private-network guard misses link-local addressesBug reported by AB was disclosed at December 22, 2025, 5:43 pm | Server-Side Request Forgery (SSRF) A vulnerability was discovered in the application that allowed authenticated users to supply a URL that the server would fetch for OpenGraph data. The "private network" guard only blocked certain IP ranges, but ignored link-local addresses, enabling server-side requests to be made to those hosts. This could have potentially allowed access to internal resources, such as cloud metadata services, depending on the server's network configuration. |