Description
CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. In version 1.7.3, ApprovalResourceService.sendWebHook reads WebHookConfig.webHookUrl from stored approval-node configuration and passes it through ApprovalFlowService.updateApprovalPostField to HttpClientUtils without the SSRF validation used by the optional testConnect path. A user with PROCESS_SETTING_ADD can configure an internal URL through POST /approval-flow/add and cause the server to request it when POST /approval-action/approve executes the approval action, enabling cloud metadata access, internal network reconnaissance, and interaction with reachable internal services. This issue is fixed in version 1.7.4.
Published: 2026-09-18
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Server‑side request forgery enabling internal network access
Action: Patch Immediately
AI Analysis

Impact

The flaw in CordysCRM’s approval‑flow webhook handling allows an attacker with PROCESS_SETTING_ADD privileges to define a custom webHookUrl that the server will request when an approval action is executed. This absence of SSRF validation lets the application contact arbitrary internal URLs, potentially exposing cloud metadata, discovering internal services, and performing unauthorized interactions with internal infrastructure. The weakness results in confidentiality leakage through outbound requests made by the server on the attacker’s behalf.

Affected Systems

This vulnerability exists in 1Panel‑dev CordysCRM version 1.7.3 and earlier. It has been mitigated in the 1.7.4 release. Systems running the affected version require an upgrade or a restrictive permission model to prevent abuse of the remediation process.

Risk and Exploitability

The CVSS score of 6.8 categorizes the issue as medium severity. EPSS data is unavailable, and the vulnerability is not listed in the CISA KEV catalog, suggesting a lower likelihood of widespread exploitation. However, the attacker must possess the PROCESS_SETTING_ADD permission, meaning that internal users or compromised accounts with that role could exploit the flaw. Once the attacker configures a malicious URL and triggers an approval action, the application will perform an HTTP request to that URL, providing a vector for reconnaissance or data exfiltration of internal services.

Generated by OpenCVE AI on September 19, 2026 at 11:12 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade CordysCRM to version 1.7.4 or later which includes the SSRF validation fix
  • Limit the PROCESS_SETTING_ADD permission to trusted administrators or remove it from untrusted roles
  • If an immediate upgrade is not possible, block or monitor outbound request endpoints used by ApprovalResourceService to restrict unintended traffic

Generated by OpenCVE AI on September 19, 2026 at 11:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
First Time appeared 1panel-dev
1panel-dev cordyscrm
Vendors & Products 1panel-dev
1panel-dev cordyscrm

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. In version 1.7.3, ApprovalResourceService.sendWebHook reads WebHookConfig.webHookUrl from stored approval-node configuration and passes it through ApprovalFlowService.updateApprovalPostField to HttpClientUtils without the SSRF validation used by the optional testConnect path. A user with PROCESS_SETTING_ADD can configure an internal URL through POST /approval-flow/add and cause the server to request it when POST /approval-action/approve executes the approval action, enabling cloud metadata access, internal network reconnaissance, and interaction with reachable internal services. This issue is fixed in version 1.7.4.
Title CordysCRM: SSRF via Approval Flow Webhook Execution due to Missing SSRF Validation at Runtime
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

1panel-dev Cordyscrm
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-22T15:42:38.566Z

Reserved: 2026-08-19T22:43:14.890Z

Link: CVE-2026-76900

cve-icon Vulnrichment

Updated: 2026-09-22T15:42:30.979Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T20:17:21.807

Modified: 2026-09-24T21:25:27.050

Link: CVE-2026-76900

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T00:15:06Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)