Server-Side Request Forgery in TDuck Survey Form by TDuckCloud
CVE-2026-92602

7.1HIGH

Key Information:

Vendor

Tduckcloud

Vendor
CVE Published:
16 September 2026

What is CVE-2026-92602?

The TDuck Survey Form up to version 5.3 is vulnerable to a server-side request forgery due to insufficient validation of webhook URLs within the WebhookConfigController. This flaw allows authenticated attackers to exploit the system by attaching webhooks to forms owned by other users, resulting in the unauthorized ability to exfiltrate form submissions to arbitrary external or internal endpoints. This breach poses significant risks to data security and user privacy.

Affected Version(s)

tduck-survey-form 0 <= 5.3

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.