Sceawere
Vulnerability Detail
CVE-2026-108523UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
SSRF in Studio-Saelix Sencho
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 4h ago
- Vendor
- Studio-Saelix
- Product
- Sencho
- Attack Type
- Server-Side Request Forgery
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was determined in Studio-Saelix Sencho up to 0.94.1. This vulnerability affects unknown code of the file outboundTarget.ts of the component git-sources Browse API Endpoint. Executing a manipulation of the argument repo_url can lead to server-side request forgery. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The presence of this vulnerability remains uncertain at this time. This patch is called 79b86ddcd4aefdd6941f098e35990ab397b13c72. It is advisable to implement a patch to correct this issue. The vendor explains: "Git repository access is an intentional, privileged administrative function. Sencho explicitly supports repositories hosted on private LAN, VPC, VPN, CGNAT, and IPv6 ULA networks. The report does not demonstrate a privilege-boundary bypass or access by an unprivileged user. We therefore dispute the CVE characterization of this behavior. As defense in depth, we have nevertheless hardened repository access. Git HTTPS and SSH connections now validate and pin DNS resolution, reject loopback, link-local, multicast, selected special-use and metadata targets, disable redirects and inherited proxy routing, and retain strict SSH host-key verification."
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-10-11T05:16:52.630Z",
"pubdate": "2026-10-11T05:16:52.630Z",
"executiveSummary": "A Server-Side Request Forgery (SSRF) vulnerability exists in Studio-Saelix Sencho up to version 0.94.1 within the git-sources Browse API Endpoint. The vulnerability originates from improper validation of the 'repo_url' argument in 'outboundTarget.ts', potentially allowing unauthorized remote actors to force the server to initiate unintended network requests. While the vendor disputes the security severity, citing that repository access is an administrative function, the vulnerability allows for potential interaction with internal resources, including those on private LANs, VPCs, VPNs, and CGNAT networks. Successful exploitation enables an attacker to leverage the server's identity to probe internal infrastructure, potentially bypassing network segmentation or accessing sensitive metadata services. Although the vendor maintains that this functionality requires administrative privilege, the lack of strict egress filtering and URI validation creates a viable attack vector for unauthorized network reconnaissance and potential data exfiltration from internal endpoints.",
"technicalDetails": "The vulnerability is located in the 'outboundTarget.ts' file within the 'git-sources' component of the Studio-Saelix Sencho API. The root cause is the insufficient sanitization and validation of the 'repo_url' parameter, which is processed by the server to facilitate Git repository synchronization. By manipulating the 'repo_url' input, a remote attacker can force the application to perform GET or SSH-based requests to arbitrary destinations.\nThe attack flow begins when an attacker identifies the 'git-sources' endpoint and submits a malicious URI via the 'repo_url' argument. In vulnerable versions, the server performs a resolution of this URL without restricting the target destination to legitimate Git hosting providers. Consequently, the server-side process can be coerced into reaching out to internal infrastructure, such as cloud metadata endpoints (e.g., 169.254.169.254), internal management interfaces, or services residing on IPv6 ULA or private address spaces.\nThe exploitation mechanism leverages the server’s role as an authorized initiator of Git-related traffic. Because the component expects to interact with repositories on diverse network topologies (LAN, VPC, VPN), it does not strictly isolate the server from internal routing. By injecting non-standard or internal targets into 'repo_url', the attacker effectively turns the Sencho server into a proxy for SSRF attacks. This bypasses client-side firewalls, as the connection originates from the trusted server environment.\nThe impact includes the ability to perform blind or semi-blind reconnaissance of internal networks, potentially revealing active services, port states, or sensitive configuration data. If the server is hosted in a cloud environment, the SSRF may lead to the exfiltration of IAM credentials or sensitive instance metadata. Authentication and privilege requirements are subject to vendor contention; however, the exposure of the API endpoint allows for remote access, significantly increasing the attack surface if the endpoint is not correctly gated by robust identity and access management (IAM) policies.\nThe vendor-provided fix, patch 79b86ddcd4aefdd6941f098e35990ab397b13c72, implements critical security hardening. This includes DNS resolution pinning to prevent DNS rebinding attacks, explicit rejection of loopback and link-local addresses, disabling of redirects and inherited proxies, and the enforcement of strict SSH host-key verification. These measures effectively close the SSRF vector by ensuring that the application only initiates outbound traffic to authorized, non-special-use targets."
}