Impact
Huginn before 2026.09.09 includes a server‑side request forgery vulnerability in the fetch_url method of the ScenarioImport feature. This flaw allows any authenticated user to submit a crafted URL, causing the application to perform a HTTP request to the target address. The attacker can therefore explore internal network services, enumerate exposed ports via error signatures, and reach cloud metadata endpoints to harvest confidential credentials.
Affected Systems
Any Huginn installation running a version earlier than 2026.09.09 is affected. Versions 2026.09.09 and later contain the fix. The vulnerable component is the ScenarioImport fetch_url method within the Huginn application, which is available in all releases prior to the specified date.
Risk and Exploitability
The CVSS score of 6.3 reflects a moderate severity. The exploit probability measured by EPSS is below 1%, indicating a low chance that a public exploit will be actively used, and the vulnerability is not listed in CISA’s KEV catalog. Because the flaw requires authenticated access to the Huginn interface, an attacker must first obtain valid credentials. Once authenticated, the attacker can simply craft a URL that is processed by fetch_url, turning the Huginn process into a proxy for outbound requests. This ability can be abused to probe local resources, discover services, or read sensitive data from cloud metadata services.
OpenCVE Enrichment