Unvalidated Base URL Vulnerability in Prowler Cloud Security Platform
CVE-2026-73264
7.6HIGH
What is CVE-2026-73264?
Prior to version 5.33.1, Prowler, a cloud security platform, exposed a vulnerability that allowed authenticated users with specific Lighthouse provider configuration access to provide an unvalidated 'base_url' for the openai_compatible provider. This occurred through the POST requests to /api/v1/lighthouse/providers and /api/v1/lighthouse/providers/{id}/connection. Consequently, the system could perform outbound API calls that included sensitive authorization details, like the API key, directed towards endpoints controlled by potential attackers or internal systems, thus heightening the risk of unauthorized access and data leakage.
Affected Version(s)
prowler < 5.33.1
