Server-Side Request Forgery in Helicone Webhook Sender Affects Jawn Users
CVE-2026-108602
5.3MEDIUM
What is CVE-2026-108602?
The Helicone product version v2025.08.21-1 features a server-side request forgery vulnerability specifically within the Jawn webhook sender. This issue allows authenticated users of the organization to exploit the system by crafting webhooks that utilize public hostnames, which can then resolve to private internal addresses. Consequently, this opens up the potential for attackers to send blind POST requests to sensitive internal HTTPS services, significantly increasing the risk of unauthorized data access and exploitation of internal systems.
Affected Version(s)
helicone 0
References
CVSS V4
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
HaiND from the Post and Telecommunication Institute of Technology
