CVE-2026-108523
Received Received - Intake

Server-Side Request Forgery in Studio-Saelix Sencho

Vulnerability report for CVE-2026-108523, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulDB

Description

A vulnerability was determined in Studio-Saelix Sencho up to 0.94.1. This vulnerability affects unknown code of the file outboundTarget.ts of the component git-sources Browse API Endpoint. Executing a manipulation of the argument repo_url can lead to server-side request forgery. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The presence of this vulnerability remains uncertain at this time. This patch is called 79b86ddcd4aefdd6941f098e35990ab397b13c72. It is advisable to implement a patch to correct this issue. The vendor explains: "Git repository access is an intentional, privileged administrative function. Sencho explicitly supports repositories hosted on private LAN, VPC, VPN, CGNAT, and IPv6 ULA networks. The report does not demonstrate a privilege-boundary bypass or access by an unprivileged user. We therefore dispute the CVE characterization of this behavior. As defense in depth, we have nevertheless hardened repository access. Git HTTPS and SSH connections now validate and pin DNS resolution, reject loopback, link-local, multicast, selected special-use and metadata targets, disable redirects and inherited proxy routing, and retain strict SSH host-key verification."

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
Studio-Saelix Sencho 0.94.0
Studio-Saelix Sencho 0.94.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a Server-Side Request Forgery (SSRF) affecting Studio-Saelix Sencho up to version 0.94.1. It exists in the POST /api/git-sources/browse endpoint where the repo_url parameter is only checked for HTTPS scheme but not restricted by host or IP. This allows authenticated attackers to force the backend to connect to arbitrary internal hosts, loopback addresses, or private network ranges, enabling network reconnaissance and port scanning from within the Sencho container.

Detection Guidance

To detect this SSRF vulnerability in Sencho, monitor network traffic from the Sencho container for outbound connections to unexpected internal or loopback addresses. Check logs for POST requests to /api/git-sources/browse with repo_url parameters pointing to internal hosts. Use commands like 'docker logs <sencho-container>' to review application logs and 'ss -tulnp' or 'netstat -tulnp' to inspect active connections from the host.

Impact Analysis

An attacker could exploit this to map your internal network, scan for open ports, or access internal services by forcing Sencho to make requests to restricted targets. This could lead to unauthorized access to sensitive systems, data exfiltration, or further attacks against internal infrastructure.

Compliance Impact

This SSRF vulnerability could violate compliance requirements by allowing unauthorized network access, potentially exposing sensitive data or systems. GDPR may be impacted if personal data is exposed, while HIPAA could be violated if protected health information is accessible through internal network breaches.

Mitigation Strategies

Immediately update Sencho to the patched version (79b86ddcd4aefdd6941f098e35990ab397b13c72) which includes DNS pinning, host validation, and restrictions on loopback/link-local addresses. Configure the SENCHO_TRUSTED_PROXY_CIDRS environment variable to restrict trusted proxies. Block outbound connections to RFC1918, loopback, and link-local ranges at the network firewall level.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108523. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart