Sceawere
Vulnerability Detail
CVE-2026-102244UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
MODSetter SurfSense SSRF Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 4h ago
- Vendor
- MODSetter
- Product
- SurfSense
- Attack Type
- Server-Side Request Forgery
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
A security flaw has been discovered in MODSetter SurfSense up to 0.0.36. Impacted is an unknown function of the file surfsense_backend/app/routes/editor_routes.py of the component Document Export Feature. Performing a manipulation results in server-side request forgery. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 0.0.36.3 is recommended to address this issue. The patch is named 2faff7b3823322a9cb6797973e6caf089386c354. The affected component should be upgraded.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-09-29T03:17:15.913Z",
"pubdate": "2026-09-29T03:17:15.913Z",
"executiveSummary": "A Server-Side Request Forgery (SSRF) vulnerability has been identified in the Document Export Feature of MODSetter SurfSense versions up to 0.0.36.\nThis security flaw allows an unauthenticated remote attacker to coerce the application server into making unauthorized outbound HTTP or network requests to arbitrary internal or external resources.\nThe vulnerability resides within the backend routing logic of the document export process, posing a significant risk to internal network segmentation and data confidentiality.\nSuccessful exploitation permits an attacker to perform internal reconnaissance, interact with local services that lack external exposure, or potentially exfiltrate sensitive data from internal systems.\nThe existence of public exploit code increases the risk of active exploitation, necessitating an immediate transition to the patched version, 0.0.36.3.\nThe attack is remotely exploitable, bypassing perimeter security by leveraging the server's trusted network identity to perform malicious requests.",
"technicalDetails": "The vulnerability is located within surfsense_backend/app/routes/editor_routes.py in the Document Export Feature. It stems from improper input validation and sanitization of user-supplied data used to construct network requests.\nIn a standard SSRF exploitation flow, the application fails to enforce an allow-list or perform validation on the destination URL parameters passed to the backend during the document export operation.\nAn attacker can manipulate input fields related to document endpoints or export targets, injecting arbitrary URLs that the SurfSense backend will attempt to resolve and retrieve.\nWhen the affected function processes the export request, it inadvertently delegates the request to the attacker-supplied destination. This causes the server to execute a GET or POST request to the specified target using its own internal server context.\nThe network exposure is significant as the application server acts as a proxy, allowing the attacker to reach internal-only network infrastructure (e.g., metadata services, internal management consoles, or databases) that are otherwise shielded from public network segments.\nBecause the server initiates these requests, they often bypass standard firewall rules and ACLs that rely on source IP verification, as the requests originate from the trusted application host.\nPost-exploitation impact includes the ability to perform port scanning on local network interfaces, identification of internal service banners, and the capture of HTTP responses that may contain sensitive configuration metadata or credentials.\nThe vulnerability affects all iterations of MODSetter SurfSense up to and including version 0.0.36. The remediation applied in patch 2faff7b3823322a9cb6797973e6caf089386c354 likely introduces strict input validation or URL filtering to prevent the application from making requests to non-whitelisted domains or private IP address ranges."
}