Description
A vulnerability has been found in chatwoot up to 4.17.1. This impacts an unknown function of the file callbacks_controller.rb of the component Shopify OAuth. The manipulation leads to server-side request forgery. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-16
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Server-Side Request Forgery (SSRF)
Action: Patch soon
AI Analysis

Impact

A flaw inside callbacks_controller.rb of the Shopify OAuth component in Chatwoot allows an attacker to craft requests that compel the server to perform arbitrary outbound calls, enabling a server‑side request forgery scenario. The vulnerability can be exploited remotely and may expose internal network resources or exfiltrate data. It is identified as CWE‑918, which signifies an uncontrolled request to an external service.

Affected Systems

Chatwoot versions up to 4.17.1 are vulnerable. The issue is reported for the entire Chatwoot code base, identified by the name Chatwoot, with affected versions unpatched as of the last update.

Risk and Exploitability

The CVSS score of 5.3 indicates a medium severity. The EPSS score is below 1 % and the vulnerability is not listed in CISA’s KEV catalog, suggesting limited exploitation in the wild. The attack vector would likely be remote; an attacker can trigger the vulnerable OAuth callback through a crafted request to the Chatwoot server without needing local privileges.

Generated by OpenCVE AI on September 17, 2026 at 21:32 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Restrict outbound network requests from the Chatwoot server to only approved external services, blocking wildcard or DNS requests that could be used by an attacker to exploit SSRF.
  • Disable the Shopify OAuth integration if it is not required, thereby removing the vulnerable callbacks_controller.rb endpoint.
  • Place a Web Application Firewall or reverse proxy in front of Chatwoot that inspects outbound traffic and blocks unexpected or unapproved HTTP requests originating from the application.

Generated by OpenCVE AI on September 17, 2026 at 21:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in chatwoot up to 4.17.1. This impacts an unknown function of the file callbacks_controller.rb of the component Shopify OAuth. The manipulation leads to server-side request forgery. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Title chatwoot Shopify OAuth callbacks_controller.rb server-side request forgery
First Time appeared Chatwoot
Chatwoot chatwoot
Weaknesses CWE-918
CPEs cpe:2.3:a:chatwoot:chatwoot:*:*:*:*:*:*:*:*
Vendors & Products Chatwoot
Chatwoot chatwoot
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Chatwoot Chatwoot
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-17T14:12:26.421Z

Reserved: 2026-09-16T12:33:40.982Z

Link: CVE-2026-92527

cve-icon Vulnrichment

Updated: 2026-09-17T14:12:09.600Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T21:17:23.170

Modified: 2026-09-17T21:12:30.593

Link: CVE-2026-92527

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:45:16Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)