CVE-2026-87821
Deferred Deferred - Pending Action

Lara Dashboard SSRF in Markdown Fetch Endpoint

Vulnerability report for CVE-2026-87821, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-09

Assigner: VulnCheck

Description

Lara Dashboard through 1.3.1 contains a server-side request forgery vulnerability in the POST /api/admin/builder/markdown/fetch endpoint that allows any authenticated user to fetch arbitrary URLs and read the response body. Attackers can read internal HTTP services and cloud metadata including IAM credentials by supplying malicious URLs without host validation or redirect restrictions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-09
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
laradashboard laradashboard to 1.3.1 (inc)
laradashboard laradashboard From 0.9.2 (inc) to 1.3.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-87821 is a Server-Side Request Forgery (SSRF) vulnerability in Lara Dashboard versions 0.9.2 through 1.3.1. It exists in the POST /api/admin/builder/markdown/fetch endpoint, allowing any authenticated user to make the server send HTTP requests to arbitrary internal or external URLs and read the full response body. The endpoint lacks proper host validation or redirect restrictions, enabling attackers to access internal services, cloud metadata (including IAM credentials), and loopback-bound services.

Detection Guidance

Check for unusual outbound HTTP requests from your LaraDashboard server, especially to internal or cloud metadata endpoints. Monitor logs for POST requests to /api/admin/builder/markdown/fetch with arbitrary URLs. Use network traffic analysis tools like tcpdump or Wireshark to inspect requests originating from the server.

Impact Analysis

This vulnerability allows attackers with low-privilege accounts to read internal HTTP services, cloud metadata (like AWS IMDSv1), and IAM credentials. They can also perform internal port scanning, enumerate services, or chain redirects to access restricted resources. On default installations with public registration, unauthenticated attackers could exploit this by creating a user account.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection principles and HIPAA's security requirements for protected health information. Exposure of IAM credentials or internal services may result in non-compliance with security controls required by these regulations.

Mitigation Strategies

Upgrade LaraDashboard to version 1.3.2 or later, which includes SSRF protection via SafeUrlValidator. Disable the markdown fetch feature if not required. Implement network-level restrictions to block outbound requests to internal or cloud metadata endpoints. Review and restrict user permissions to minimize access to the vulnerable endpoint.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87821. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart