Unauthenticated Server-Side Request Forgery in Verba RAG Application by Verba
CVE-2026-65318
9.2CRITICAL
What is CVE-2026-65318?
The Verba RAG application version 2.1.3 is vulnerable to an unauthenticated server-side request forgery (SSRF) issue. This vulnerability allows attackers to connect to the /ws/import_files WebSocket endpoint without any authentication. By specifying malicious URLs within the HTMLReader configuration, attackers can manipulate the backend into issuing arbitrary HTTP GET requests. This could enable them to access sensitive internal resources, such as database endpoints or cloud instance metadata services, thereby exposing critical credentials.
Affected Version(s)
Verba 0 <= 2.1.3
