Impact
The issue is a server‑side request forgery vulnerability in hcengineering Huly Platform 0.7.382, located in the Import Endpoint module. An attacker can trigger the server to make arbitrary outbound HTTP requests by sending a crafted payload, allowing control over traffic from the server. This flaw provides a moderate risk to confidentiality and integrity, as attackers could exfiltrate data or send requests to arbitrary internal resources.
Affected Systems
hcengineering Huly Platform version 0.7.382 is affected. The vulnerability resides in the component Import Endpoint within file server/front/src/index.ts. No other versions or products are known to be impacted at this time.
Risk and Exploitability
The CVSS score of 5.3 indicates medium severity. The exploit is publicly available, can be triggered remotely, and no EPSS data is provided. The issue is not listed in CISA’s KEV catalog. The lack of vendor response suggests that the exploit is likely still actionable. Attackers could leverage it to force the platform to reach internal services or exfiltrate information.
OpenCVE Enrichment