Server-Side Request Forgery Vulnerability in Stigmem by Eidetic Labs
CVE-2026-76239
5.3MEDIUM
What is CVE-2026-76239?
Stigmem versions prior to 0.9.0a11 are susceptible to a server-side request forgery (SSRF) vulnerability. This flaw arises from the lack of validation on the delivery_address parameter during the creation of webhook subscriptions. Authenticated users can exploit this vulnerability to direct requests to internal loopback or private network addresses. Consequently, an attacker could initiate matching fact-change events, prompting the Stigmem server to send server-side HTTP POST requests to sensitive internal services, thereby facilitating blind SSRF attacks against localhost and other private network endpoints.
Affected Version(s)
stigmem 0 < 0.9.0a11
stigmem 0.9.0a11
