Impact
The vulnerability exists in the resolve-custom-domain-rewrite.ts file of the OpenstatusHQ Openstatus platform. By manipulating the custom domain rewrite logic, an attacker can cause the server to send outbound HTTP requests to arbitrary URLs. The attack may be initiated remotely, as the description indicates that a crafted remote request can trigger the flaw. The result is that the application performs server‑side request forgery, potentially giving an attacker the ability to reach internal or external resources and exfiltrate data or pivot further into the environment. This issue is categorized as CWE‑918.
Affected Systems
OpenstatusHQ’s Openstatus platform is vulnerable in all releases up to commit f04c827112f30a11d571ebdad3892826034d6265. Because the product follows a rolling release model, discrete version numbers are not available; the fix is identified by commit 86f370c9c20074c3c3fdec53a359874b8e670fd4. Any deployment that has not yet incorporated that commit remains susceptible.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity rating. The EPSS score is reported as less than 1%, which suggests a very low probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. Nonetheless, the flaw can be triggered remotely and allows the server to resolve arbitrary URLs, creating an opportunity for further attacks. Exploitation would involve sending a crafted request to the exposed endpoint, causing the server to contact a specified target and potentially exposing internal or public networks to the attacker.
OpenCVE Enrichment