Impact
A flaw inside callbacks_controller.rb of the Shopify OAuth component in Chatwoot allows an attacker to craft requests that compel the server to perform arbitrary outbound calls, enabling a server‑side request forgery scenario. The vulnerability can be exploited remotely and may expose internal network resources or exfiltrate data. It is identified as CWE‑918, which signifies an uncontrolled request to an external service.
Affected Systems
Chatwoot versions up to 4.17.1 are vulnerable. The issue is reported for the entire Chatwoot code base, identified by the name Chatwoot, with affected versions unpatched as of the last update.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity. The EPSS score is below 1 % and the vulnerability is not listed in CISA’s KEV catalog, suggesting limited exploitation in the wild. The attack vector would likely be remote; an attacker can trigger the vulnerable OAuth callback through a crafted request to the Chatwoot server without needing local privileges.
OpenCVE Enrichment