mediumCVSS 4.7Vulnerability

CVE-2026-5469

A weakness has been identified in Casdoor 2.356.0. This vulnerability affects unknown code of the component Webhook URL Handler. Executing a manipulation can lead to server-side request forgery. The attack can be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.

Properties

severity
medium
summary
Casdoor vulnerable to SSRF via crafted Webhook URL
epss_score
0.00301
cvss_score
4.7
ghsa_published
2026-04-03T15:30:31Z
source_url
https://github.com/advisories/GHSA-p8c7-hjc4-gwf8
ghsa_updated
2026-04-10T15:36:19Z
ghsa_id
GHSA-p8c7-hjc4-gwf8
cve_id
CVE-2026-5469
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
is_ghsa_only
false
epss_percentile
0.22863

Related Entities (4)

ENRICHED_BY (1)

[Source]FIRST EPSS

REPORTED_BY (1)

[Source]GitHub Advisory Database

AFFECTS (1)

[Software]go/github.com/casdoor/casdoor

HAS_WEAKNESS (1)

[Weakness]Server-Side Request Forgery (SSRF)

Explore deeper with Ninja Signal's threat intelligence graph