Impact
The vulnerability in Huly Platform through version 0.7.426 allows authenticated workspace members to supply arbitrary URLs to the print service, which internally renders the requested content using Puppeteer and returns it as a PDF or image. Because the service lacks hostname allowlist validation, an attacker can trigger the service to request internal network hosts or metadata services, thereby leaking sensitive data or enumerating internal infrastructure. The flaw is a classic SSRF flaw. The impact, therefore, is that an attacker can read internal resources and potentially move laterally inside the corporate network.
Affected Systems
The affected product is Huly Platform (hcengineering:platform) version 0.7.426. Any installation that allows authenticated workspace members to invoke the print endpoint without an allowlist for target hostnames is vulnerable. No other product versions are explicitly listed as affected in the available data.
Risk and Exploitability
The CVSS score for this vulnerability is 6.3, which places it in the moderate range. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires the attacker to be an authenticated workspace member with access to the print service; from there, the attacker supplies a crafted URL targeting an internal host. Upon the service rendering the request, the internal host's response will be embedded in the downloadable file, allowing the attacker to view sensitive data that should not be externally accessible. The exploit is achievable with standard operational access and therefore poses a tangible risk to the confidentiality of internal services.
OpenCVE Enrichment