Description
Huginn before 2026.09.09 contains a server-side request forgery vulnerability in the fetch_url method of ScenarioImport that allows authenticated users to make arbitrary HTTP requests by submitting crafted URLs. Attackers can probe internal network services, enumerate ports via error signatures, and access cloud metadata endpoints to retrieve sensitive credentials.
Published: 2026-07-20
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Server‑Side Request Forgery that permits authenticated users to retrieve arbitrary network resources and internal metadata
Action: Apply Patch
AI Analysis

Impact

Huginn before 2026.09.09 includes a server‑side request forgery vulnerability in the fetch_url method of the ScenarioImport feature. This flaw allows any authenticated user to submit a crafted URL, causing the application to perform a HTTP request to the target address. The attacker can therefore explore internal network services, enumerate exposed ports via error signatures, and reach cloud metadata endpoints to harvest confidential credentials.

Affected Systems

Any Huginn installation running a version earlier than 2026.09.09 is affected. Versions 2026.09.09 and later contain the fix. The vulnerable component is the ScenarioImport fetch_url method within the Huginn application, which is available in all releases prior to the specified date.

Risk and Exploitability

The CVSS score of 6.3 reflects a moderate severity. The exploit probability measured by EPSS is below 1%, indicating a low chance that a public exploit will be actively used, and the vulnerability is not listed in CISA’s KEV catalog. Because the flaw requires authenticated access to the Huginn interface, an attacker must first obtain valid credentials. Once authenticated, the attacker can simply craft a URL that is processed by fetch_url, turning the Huginn process into a proxy for outbound requests. This ability can be abused to probe local resources, discover services, or read sensitive data from cloud metadata services.

Generated by OpenCVE AI on September 21, 2026 at 07:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Huginn to version 2026.09.09 or later to address the SSRF flaw.
  • Limit access to the ScenarioImport feature by granting it only to users with elevated privileges, or disable the feature entirely for untrusted users.
  • Implement network segmentation or firewall rules to restrict outbound HTTP/HTTPS traffic from the Huginn process, preventing unintended connections to internal or external systems.

Generated by OpenCVE AI on September 21, 2026 at 07:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description Huginn through 2022.08.18 contains a server-side request forgery vulnerability in the fetch_url method of ScenarioImport that allows authenticated users to make arbitrary HTTP requests by submitting crafted URLs. Attackers can probe internal network services, enumerate ports via error signatures, and access cloud metadata endpoints to retrieve sensitive credentials. Huginn before 2026.09.09 contains a server-side request forgery vulnerability in the fetch_url method of ScenarioImport that allows authenticated users to make arbitrary HTTP requests by submitting crafted URLs. Attackers can probe internal network services, enumerate ports via error signatures, and access cloud metadata endpoints to retrieve sensitive credentials.
Title Huginn 2022.08.18 SSRF via ScenarioImport fetch_url Method Huginn < 2026.09.09 SSRF via ScenarioImport fetch_url Method
References

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Huginn
Huginn huginn
Vendors & Products Huginn
Huginn huginn

Tue, 21 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 20 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Description Huginn through 2022.08.18 contains a server-side request forgery vulnerability in the fetch_url method of ScenarioImport that allows authenticated users to make arbitrary HTTP requests by submitting crafted URLs. Attackers can probe internal network services, enumerate ports via error signatures, and access cloud metadata endpoints to retrieve sensitive credentials.
Title Huginn 2022.08.18 SSRF via ScenarioImport fetch_url Method
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:18:10.197Z

Reserved: 2026-07-18T12:34:08.780Z

Link: CVE-2026-63769

cve-icon Vulnrichment

Updated: 2026-07-21T13:39:03.503Z

cve-icon NVD

Status : Deferred

Published: 2026-07-20T19:17:29.633

Modified: 2026-09-14T20:16:48.943

Link: CVE-2026-63769

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T07:45:11Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)