Server-Side Request Forgery in Verba RAG Application by Verba
CVE-2026-65317
9.2CRITICAL
What is CVE-2026-65317?
The Verba RAG application version 2.1.3 suffers from a server-side request forgery vulnerability, which, when exploited, allows unauthenticated attackers to manipulate the server into making arbitrary HTTP requests. This is achieved by crafting a malicious Origin header that bypasses the localhost origin check in the API middleware. Attackers can provide any Origin value prefixed with a quotation mark and submit arbitrary host and port parameters targeting the /api/connect endpoint. As a result, the server becomes susceptible to issuing outbound GET requests to attacker-controlled systems, potentially leading to unauthorized access and data leakage.
Affected Version(s)
Verba 0 <= 2.1.3
