Description
A vulnerability was identified in appsmithorg appsmith up to 1.97. Impacted is the function computeDisallowedHosts of the file app/server/appsmith-interfaces/src/main/java/com/appsmith/util/WebClientUtils.java of the component Dashboard. Such manipulation leads to server-side request forgery. The attack may be launched remotely. The exploit is publicly available and might be used. Upgrading to version 1.99 is recommended to address this issue. The affected component should be upgraded. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Published: 2026-04-02
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Server-side Request Forgery
Action: Apply Patch
AI Analysis

Impact

The vulnerability resides in the computeDisallowedHosts function of the Dashboard component; an attacker can manipulate input to trigger the server to produce HTTP requests to arbitrary hosts, leading to server‑side request forgery, which allows exfiltration, internal service interaction, or network reconnaissance, and aligns with CWE‑918.

Affected Systems

It affects Appsmith built by appsmithorg; all releases up to version 1.97 contain the issue and users should upgrade to version 1.99 or later, which contains the patch for the computeDisallowedHosts function in the Dashboard module.

Risk and Exploitability

With a CVSS score of 6.9 the vulnerability has medium severity; attackers can launch the exploit remotely and public exploits exist, suggesting moderate likelihood; EPSS data is missing and it is not in KEV, yet the public exploit warrants immediate attention, and the attack vector is likely remote via the web interface with no local privilege needed.

Generated by OpenCVE AI on April 2, 2026 at 22:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Appsmith to version 1.99 or newer, which includes the fixed function.
  • After upgrading, confirm that computeDisallowedHosts no longer allows arbitrary host resolution by testing with known internal addresses.
  • Monitor outbound network traffic from the application for any unexpected requests to potential internal or external resources.

Generated by OpenCVE AI on April 2, 2026 at 22:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 02 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in appsmithorg appsmith up to 1.97. Impacted is the function computeDisallowedHosts of the file app/server/appsmith-interfaces/src/main/java/com/appsmith/util/WebClientUtils.java of the component Dashboard. Such manipulation leads to server-side request forgery. The attack may be launched remotely. The exploit is publicly available and might be used. Upgrading to version 1.99 is recommended to address this issue. The affected component should be upgraded. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Title appsmithorg appsmith Dashboard WebClientUtils.java computeDisallowedHosts server-side request forgery
First Time appeared Appsmith
Appsmith appsmith
Weaknesses CWE-918
CPEs cpe:2.3:a:appsmith:appsmith:*:*:*:*:*:*:*:*
Vendors & Products Appsmith
Appsmith appsmith
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Appsmith Appsmith
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-04-03T12:59:56.016Z

Reserved: 2026-04-02T11:05:13.808Z

Link: CVE-2026-5418

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-04-02T19:21:36.737

Modified: 2026-04-03T16:10:23.730

Link: CVE-2026-5418

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-03T09:16:41Z

Weaknesses