Impact
The vulnerability resides in the computeDisallowedHosts function of the Dashboard component; an attacker can manipulate input to trigger the server to produce HTTP requests to arbitrary hosts, leading to server‑side request forgery, which allows exfiltration, internal service interaction, or network reconnaissance, and aligns with CWE‑918.
Affected Systems
It affects Appsmith built by appsmithorg; all releases up to version 1.97 contain the issue and users should upgrade to version 1.99 or later, which contains the patch for the computeDisallowedHosts function in the Dashboard module.
Risk and Exploitability
With a CVSS score of 6.9 the vulnerability has medium severity; attackers can launch the exploit remotely and public exploits exist, suggesting moderate likelihood; EPSS data is missing and it is not in KEV, yet the public exploit warrants immediate attention, and the attack vector is likely remote via the web interface with no local privilege needed.
OpenCVE Enrichment