Server-Side Request Forgery in AIL Framework Crawler Submission Functionality
CVE-2026-76164

7.1HIGH

Key Information:

Vendor
CVE Published:
19 August 2026

What is CVE-2026-76164?

The AIL Framework contains a vulnerability allowing authenticated low-privileged users to exploit the crawler submission functionality, enabling SSRF attacks. This flaw permits users to submit arbitrary URLs for crawling without sufficient validation, potentially accessing restricted network locations, including local and private addresses. Attackers can manipulate the crawler to make HTTP(S) requests to internal services, leading to possible disclosure of sensitive data, including internal application information and cloud metadata. With a recent patch, validations have been introduced to reject URLs linking to non-global IP addresses, thereby mitigating these potential exploits.

Affected Version(s)

ail-framework 0 < 7.0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tomás Illuminati
geo-chen
Aurelien Thirion
.