Impact
The vulnerability resides in the PullMD REST API at the /api endpoint of AeternaLabsHQ PullMD 3.2.0. A crafted request containing a manipulated url parameter forces the server to perform an unwanted HTTP request to an arbitrary target, enabling attacks such as data exfiltration or internal network probing. The weakness is a classic server-side request forgery, classified as CWE‑918. The impact includes potential confidentiality, integrity, and availability damage if the forged request targets sensitive resources.
Affected Systems
AeternaLabsHQ PullMD, version 3.2.0, and any environment that has the REST API exposed. Version 3.3.0 addresses the issue; all earlier releases remain vulnerable.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, and the EPSS score is not available, leaving the exploitation probability uncertain but measurable risk present. The vulnerability is not listed in CISA’s KEV catalog, suggesting no known widespread exploitation yet, yet the attack can be launched from anywhere and has been disclosed publicly. The likely attack vector is remote, from an external client that directs the PullMD server to reach arbitrary URLs.
OpenCVE Enrichment