Server-Side Request Forgery in TDuck Survey Form by TDuckCloud
CVE-2026-92602
7.1HIGH
What is CVE-2026-92602?
The TDuck Survey Form up to version 5.3 is vulnerable to a server-side request forgery due to insufficient validation of webhook URLs within the WebhookConfigController. This flaw allows authenticated attackers to exploit the system by attaching webhooks to forms owned by other users, resulting in the unauthorized ability to exfiltrate form submissions to arbitrary external or internal endpoints. This breach poses significant risks to data security and user privacy.
Affected Version(s)
tduck-survey-form 0 <= 5.3
