PromptHub SSRF via IPv6 bypass in skills fetch-remote endpoint (CVE-2026-42261)
PromptHub versions 0.4.9 through 0.5.3 expose an authenticated POST /api/skills/fetch-remote endpoint that fetches a user-supplied URL server-side and reflects the response, with SSRF protections bypassable via alternate IPv6 representations. Any authenticated user — including self-registered users where ALLOW_REGISTRATION=true — could reach loopback, RFC1918 and link-local addresses; fixed in version 0.5.4.
Disclosed 8 May 2026 · Record updated 13 September 2026
Impact
Authenticated users could make the server issue requests to internal/private network addresses and receive up to 5 MB of the response body, enabling access to internal services.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-42261
