Server-Side Request Forgery Vulnerability in AeternaLabsHQ PullMD REST API
CVE-2026-76795
Key Information:
- Vendor
Aeternalabshq
- Status
- Vendor
- CVE Published:
- 20 August 2026
Badges
What is CVE-2026-76795?
A critical vulnerability has been identified in the PullMD product from AeternaLabsHQ, specifically within the REST API Endpoint feature. The issue arises from the improper handling of the 'url' argument in the API, which can be exploited for server-side request forgery (SSRF). This allows attackers to manipulate server requests, which could lead to disclosing sensitive information or further compromise the server's security. The vulnerability can be exploited remotely, making it essential for users to upgrade to version 3.3.0 to address the flaw. The patch identifier is 96448894cc93ccecb0bdcbf263a9d25390a8455e.
Affected Version(s)
PullMD 3.2.0
PullMD 3.3.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
