Description
Server-Side request forgery (SSRF) vulnerability in HAVELSAN Inc. Sef - AI Chatbot Platform allows Server Side Request Forgery.

This issue affects Sef - AI Chatbot Platform: before 2.1. NOTE: The vendor was contacted and it was learned that the product is not supported.
Published: 2026-10-02
Score: 4.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Server‑Side Request Forgery
Action: Apply Patch
AI Analysis

Impact

The updated vulnerability description indicates that the Sef – AI Chatbot Platform's tool runner API is vulnerable to Server‑Side Request Forgery, allowing an attacker to instruct the server to make HTTP requests to arbitrary destinations. This flaw can expose internal services, leak sensitive data, and provide a path to otherwise inaccessible networks. The weakness is a CWE‑918 type.

Affected Systems

HAVELSAN Inc.’s Sef – AI Chatbot Platform, for all versions earlier than 2.1. The API endpoint responsible for tool execution is exposed publicly and is the source of the SSRF vulnerability.

Risk and Exploitability

The CVSS score of 4.9 indicates a moderate severity flaw, and the EPSS score is 0.00274, indicating an extremely low exploitation probability. The platform is not listed in the CISA KEV catalog. The likely attack vector is an externally‑initiated request to the tool runner endpoint, exploiting the lack of validation on target URLs. Attacks would require an attacker’s ability to reach the platform but do not need privileged internal access.

Generated by OpenCVE AI on October 2, 2026 at 15:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Sef – AI Chatbot Platform to version 2.1 or later to eliminate the SSRF flaw.
  • If an upgrade cannot be performed immediately, block the tool runner’s outbound traffic to internal networks and disallow the loopback interface.
  • Implement a strict outbound request filter or proxy that validates destinations, restricting the platform to approved URLs only.

Generated by OpenCVE AI on October 2, 2026 at 15:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Havelsan
Havelsan sef - Ai Chatbot Platform
Vendors & Products Havelsan
Havelsan sef - Ai Chatbot Platform

Fri, 02 Oct 2026 14:45:00 +0000

Type Values Removed Values Added
Description Server-Side request forgery (SSRF) vulnerability in HAVELSAN Inc. Sef - AI Chatbot Platform allows Server Side Request Forgery. This issue affects Sef - AI Chatbot Platform: before 2.1. Server-Side request forgery (SSRF) vulnerability in HAVELSAN Inc. Sef - AI Chatbot Platform allows Server Side Request Forgery. This issue affects Sef - AI Chatbot Platform: before 2.1. NOTE: The vendor was contacted and it was learned that the product is not supported.

Fri, 02 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 02 Oct 2026 09:15:00 +0000

Type Values Removed Values Added
Description Server-Side request forgery (SSRF) vulnerability in HAVELSAN Inc. Sef - AI Chatbot Platform allows Server Side Request Forgery. This issue affects Sef - AI Chatbot Platform: before 2.1.
Title API Tool Runner SSRF in HAVELSAN's Sef - AI Chatbot Platform
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Havelsan Sef - Ai Chatbot Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-10-02T14:37:39.177Z

Reserved: 2026-08-26T12:33:11.120Z

Link: CVE-2026-80464

cve-icon Vulnrichment

Updated: 2026-10-02T13:15:45.855Z

cve-icon NVD

Status : Deferred

Published: 2026-10-02T09:16:44.967

Modified: 2026-10-02T15:17:11.103

Link: CVE-2026-80464

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T16:00:13Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)