Sceawere

Vulnerability Detail

CVE-2026-19352UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

LosslessCut HTTP API SSRF

Vulnerability Metadata

Severity
Low
Score / CVSS
3.1
Creation Date
3h ago
Vendor
mifi
Product
lossless-cut
Attack Type
Server-Side Request Forgery
Vector String
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
HIGH

Narrative and Response

Description

A vulnerability was determined in mifi lossless-cut up to 3.69.0. Affected by this issue is some unknown functionality of the file src/main/httpServer.ts of the component Built-in HTTP API Service. Executing a manipulation can lead to server-side request forgery. The attack requires access to the local network. This attack is characterized by high complexity. The exploitation is known to be difficult. The exploit has been publicly disclosed and may be utilized. This patch is called 260802348955231442c4bae6c2d9d8ede947af0a. It is best practice to apply a patch to resolve this issue. The project maintainer provides this view: "I'm not sure that this is a critical vulnerability, because it is behind an experimental CLI flag and the NTLM behavior isn't really a LosslessCut bug." The CVSS vector reflects the high level of pre-requisites.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "3.1",
  "pubDate": "2026-08-09T13:16:50.927Z",
  "pubdate": "2026-08-09T13:16:50.927Z",
  "executiveSummary": "A vulnerability has been identified in mifi lossless-cut up to 3.69.0, specifically within the Built-in HTTP API Service located at src/main/httpServer.ts. This flaw introduces a server-side request forgery (SSRF) vulnerability that can be exploited by an adversary to interact with unauthorized resources.\nThe risk implications are constrained by specific environmental prerequisites. Successful exploitation requires the attacker to have access to the local network where the target instance is running. Furthermore, the attack is characterized by high complexity, and the actual exploitation process is considered difficult.\nThe vulnerability affects systems running versions up to 3.69.0 where the experimental HTTP API functionality is exposed. Project maintainers noted that the feature resides behind an experimental command-line interface flag. Despite the high prerequisites and experimental nature of the feature, public disclosure of an exploit increases the urgency for proper risk management.\nOrganizations utilizing the affected software should implement available vendor patches or restrict access to the experimental built-in HTTP server to mitigate potential unauthorized request abuse.",
  "technicalDetails": "The vulnerability resides within the Built-in HTTP API Service component of mifi lossless-cut, specifically inside the source file src/main/httpServer.ts. The root cause stems from improper handling or validation of incoming HTTP requests processed by the application's internal server, which allows malicious manipulation of request parameters to force the server into initiating unauthorized outbound connections.\nThe affected versions include all releases of mifi lossless-cut up to version 3.69.0. The vulnerable component operates as an internal HTTP server that is typically initialized via an experimental command-line interface flag, meaning it is not active by default in standard user workflows.\nRegarding network exposure and prerequisites, the attack requires the threat actor to have direct access to the local network hosting the vulnerable application. The exploitation vector demands high complexity and is difficult to execute reliably, reflecting the strict preconditions required for successful payload transmission and interaction.\nThe step-by-step attack flow involves the following phases: First, an attacker establishes a network position within the local network boundary of the target running mifi lossless-cut with the experimental HTTP API service enabled. Second, the attacker crafts a malicious payload targeting the httpServer.ts component via the exposed HTTP interface. Third, by leveraging unspecified functionality within the API, the attacker forces the server to process and issue arbitrary outbound requests to internal or external destinations, resulting in server-side request forgery. Finally, the post-exploitation impact includes potential information disclosure or unauthorized interaction with internal network services that the host machine can access."
}
CVE-2026-19352: LosslessCut HTTP API SSRF (LOW Severity, CVSS: 3.1) - Sceawere