Sceawere
Vulnerability Detail
CVE-2026-100893UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Privoce VoceChat Server SSRF Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.3
- Creation Date
- 6h ago
- Vendor
- Privoce
- Product
- VoceChat Server
- Attack Type
- Server-Side Request Forgery
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was determined in Privoce VoceChat Server up to 0.5.36. This vulnerability affects the function open_graph::fetch of the file src/api/resource.rs of the component open_graphic_parse Endpoint. Executing a manipulation of the argument url can lead to server-side request forgery. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.3",
"pubDate": "2026-09-28T02:17:19.020Z",
"pubdate": "2026-09-28T02:17:19.020Z",
"executiveSummary": "A Server-Side Request Forgery (SSRF) vulnerability has been identified in the Privoce VoceChat Server, affecting all versions up to and including 0.5.36.\nThe vulnerability resides within the open_graph::fetch function, which fails to adequately sanitize user-supplied input provided to the url argument.\nBy manipulating this argument, an unauthenticated, remote attacker can force the server to initiate arbitrary HTTP requests to internal or external resources.\nThis flaw allows for unauthorized network scanning, interaction with internal services protected by firewalls, and potential exfiltration of sensitive configuration data or metadata.\nThe risk is categorized as high, particularly because the exploit vector is publicly disclosed and requires no authentication to execute.\nThe vendor has been notified of this security deficiency but has failed to provide a response or corrective patch, leaving deployments exposed to ongoing exploitation attempts.",
"technicalDetails": "The vulnerability exists within the open_graphic_parse endpoint, specifically inside the open_graph::fetch function located in src/api/resource.rs. The root cause is the improper validation and sanitization of the url parameter passed to the server-side request initiation logic.\nWhen a user submits a URL to the open_graphic_parse endpoint, the application server attempts to fetch Open Graph metadata from the provided address. Because the server does not enforce an allow-list of domains, implement strict protocol validation, or resolve internal hostnames against an allow-list, it becomes susceptible to SSRF.\nThe attack flow begins when an attacker sends a crafted request to the vulnerable endpoint with a malicious payload in the url parameter. Instead of providing a public Open Graph URL, the attacker provides internal IP addresses (e.g., 127.0.0.1, 169.254.169.254) or internal network hostnames.\nUpon receipt, the open_graph::fetch function executes the request, effectively using the server as a proxy to interact with resources within the internal network segment. This bypasses network-level security controls, such as firewalls or network access control lists (ACLs) that would otherwise block direct access to these internal resources.\nThe payload behavior involves the server establishing a connection to the specified target and potentially returning the body of the response to the attacker, depending on how the application handles the fetch results. This enables the attacker to perform service discovery, fingerprint internal services, or interact with metadata services (such as those used in cloud environments to retrieve identity tokens).\nGiven that this vulnerability is remotely exploitable and requires no prior authentication, it poses a critical risk to the integrity and confidentiality of the internal network infrastructure hosting the VoceChat Server. There are no known privilege requirements for exploitation, and the server’s role as an intermediary for these requests allows the attacker to obfuscate their activities behind the server's identity."
}