Dradis CE SSRF via unrestricted AI provider address
An authorization bypass in Dradis Community Edition allows authenticated non-admin users to create arbitrary AI providers and trigger server-side request forgery attacks. The SSRF vulnerability permits reading response bodies from internal hosts via reflected error messages.
Disclosed 25 August 2026 · Record updated 13 September 2026
Impact
Authenticated non-admin users can perform SSRF attacks against internal hosts and read response bodies through error message reflection.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-79788
