Server-Side Request Forgery Protection Bypass in ClaraVerse by ClaraVerse
CVE-2026-102879
5.3MEDIUM
What is CVE-2026-102879?
ClaraVerse versions up to 0.3.1 are susceptible to server-side request forgery (SSRF) protection bypasses in the download_file and scrape_web agent tools. This vulnerability allows authenticated users to circumvent hostname validation and IPv6 transition address filtering. As a result, attackers can manipulate the server into making unauthorized requests to internal services and cloud instance metadata endpoints, potentially exposing sensitive data.
Affected Version(s)
ClaraVerse 0 <= 0.3.1
