Description
The Playground feature of Zilliz Attu before 3.0.0 allows SSRF (proxying of requests to private IP addresses).
Published: 2026-10-02
Score: 4 Medium
EPSS: n/a
KEV: No
Impact: Remote Server Side Request Forgery
Action: Apply Patch
AI Analysis

Impact

The vulnerability resides in the Playground feature of Zilliz Attu versions prior to 3.0.0. An unauthenticated attacker can construct a request that is proxied by the application to arbitrary URLs, enabling the attacker to reach private IP addresses and internal services. This SSRF flaw could allow data exfiltration, internal service enumeration, or further exploitation of downstream systems. The weakness is classified as CWE-1289, reflecting the improper handling of request routing that bypasses restrictions.

Affected Systems

Systems running Zilliz Attu version 2.x and older that have the Playground feature enabled are affected. The vulnerability applies to every instance where the Playground endpoint is reachable, regardless of network segmentation. An installation using any of the default configurations prior to the release of version 3.0.0 falls within the affected scope.

Risk and Exploitability

The CVSS score of 4 indicates a moderate severity, and the EPSS score is currently unavailable, making it difficult to gauge current exploitation prevalence. The vulnerability is not listed in the CISA KIÉ catalog. The attack vector is likely to be external, targeting the publicly exposed Playground API, though it can be leveraged from within a network if the feature is accessible. While the flaw alone may not trigger high-impact damage, it can serve as a foothold for attackers to access internal resources, making mitigation recommended.

Generated by OpenCVE AI on October 2, 2026 at 23:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Zilliz Attu to version 3.0.0 or later, which fixes the SSRF in the Playground feature.
  • If a patch is not yet available, disable or remove the Playground feature from your deployment to block the exposed proxy functionality.
  • Implement network segmentation or firewall rules to block the application from reaching internal IP ranges, adding an additional barrier against exploitation.

Generated by OpenCVE AI on October 2, 2026 at 23:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 23:45:00 +0000

Type Values Removed Values Added
Title SSRF via Playground in Zilliz Attu before 3.0.0

Fri, 02 Oct 2026 22:30:00 +0000

Type Values Removed Values Added
Description The Playground feature of Zilliz Attu before 3.0.0 allows SSRF (proxying of requests to private IP addresses).
Weaknesses CWE-1289
References
Metrics cvssV3_1

{'score': 4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-10-02T22:08:31.771Z

Reserved: 2026-10-02T22:08:31.093Z

Link: CVE-2026-105048

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T23:16:57.787

Modified: 2026-10-02T23:16:57.787

Link: CVE-2026-105048

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T23:30:10Z

Weaknesses
  • CWE-1289

    Improper Validation of Unsafe Equivalence in Input