Impact
A server‑side request forgery exists in the AIL Framework crawler. An authenticated user who can submit crawler tasks can specify any URL without validation, causing the framework to fetch data from loopback, RFC1918 private, link‑local or cloud metadata addresses. The retrieved content—including HTML, screenshots and HAR files—is returned through the crawler interface, making the SSRF non‑blind and permitting leakage of internal application data, service information, or cloud instance metadata and credentials.
Affected Systems
The issue is present in the AIL Framework, an open‑source cybersecurity analysis platform. No specific version numbers are provided, so all releases that include the crawler module are potentially affected. Systems that expose the crawler interface to even low‑privileged users are vulnerable.
Risk and Exploitability
The CVSS score of 7.1 denotes high severity, but the EPSS score is below 1 %, indicating low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Attackers must be authenticated and have access to the crawler interface, yet they can pivot the AIL server into internal networks, which is a significant risk for organizations that have exposed crawler functionality.
OpenCVE Enrichment