Impact
A server‑side request forgery flaw exists in the embedding endpoint configuration of Odysseus. An attacker with administrative privileges can supply arbitrary URLs that bypass scheme or host validation, causing the server to request resources inside the internal network. If the attacker points the endpoint at internal services or cloud metadata endpoints, the server may return parts of those responses, enabling disclosure of sensitive internal data or configuration.
Affected Systems
Odysseus, provided by odysseus-dev, is vulnerable in all releases prior to commit 87babb5. The issue is limited to the embedding endpoint configuration as accessed by users with administrative rights.
Risk and Exploitability
The CVSS score of 6.1 indicates a moderate severity vulnerability. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires administrative access to the application and the ability to submit configuration changes. Once performed, the attacker can initiate outbound requests to any internal address, potentially reading responses from cloud instance metadata, internal APIs, or other reachable hosts. The attack vector is inferred to be server‑internal due to the need for administrative privileges, but the risk of internal data exposure is significant.
OpenCVE Enrichment