Server-Side Request Forgery in Lightdash Affects Scheduled Delivery Webhook Functionality
CVE-2026-72846
5.3MEDIUM
What is CVE-2026-72846?
A vulnerability in Lightdash allows attackers to exploit unvalidated webhook URLs in scheduled deliveries, resulting in potential Server-Side Request Forgery (SSRF). The compromised functionality exposes internal services to attackers by enabling the delivery server to issue POST requests to any specified URL, including private and link-local addresses. This also allows attackers to infer the existence of internal services based on error messages while concealing responses from the original requester. To mitigate this risk, users are urged to upgrade to version 1.146.4, which implements URL validation for these webhook requests.
Affected Version(s)
lightdash 0 < 1.146.4
lightdash 1.146.4
