Dark C0d3rs
HackerOne Disclosed Reports - 2025-12-22 - Printable Version

+- Dark C0d3rs (https://darkcoders.wiki)
+-- Forum: Exploit Log (https://darkcoders.wiki/Forum-Exploit-Log)
+--- Forum: Research Papers/Vulnerability reports (https://darkcoders.wiki/Forum-Research-Papers-Vulnerability-reports)
+--- Thread: HackerOne Disclosed Reports - 2025-12-22 (/Thread-HackerOne-Disclosed-Reports-2025-12-22)



HackerOne disclosed reports - 2025-12-22 - hashXploiter - 12-23-2025

Logo
Medium
resolved

Link unfurling calls out to arbitrary URLs and the private-network guard misses link-local addresses


Bug reported by AB was disclosed at December 22, 2025, 5:43 pm   |   Server-Side Request Forgery (SSRF)

A vulnerability was discovered in the application that allowed authenticated users to supply a URL that the server would fetch for OpenGraph data. The "private network" guard only blocked certain IP ranges, but ignored link-local addresses, enabling server-side requests to be made to those hosts. This could have potentially allowed access to internal resources, such as cloud metadata services, depending on the server's network configuration.