Server-Side Request Forgery Vulnerability in LimeSurvey by LimeSurvey GmbH
CVE-2026-63107
Key Information:
- Vendor
Limesurvey
- Status
- Vendor
- CVE Published:
- 20 July 2026
Badges
What is CVE-2026-63107?
LimeSurvey versions 6.17.10 and 7.0.4 are vulnerable to server-side request forgery (SSRF) through their REST API. This vulnerability allows authenticated users to manipulate the Host header, enabling the server to execute arbitrary HTTP requests. Exploiting this flaw could permit attackers to access internal network services and cloud metadata endpoints, potentially leading to the leakage of sensitive credentials, such as IAM tokens, contained within instance metadata services.
Affected Version(s)
LimeSurvey 0 <= 6.17.10
LimeSurvey 0 <= 6.17.10
LimeSurvey 0 <= 7.0.4
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
