Impact
The flaw in NonceGeek dim‑sum‑app’s textSearchV2Handler permits an attacker to alter the supabase_url argument, causing the server to perform an arbitrary HTTP request to any destination. This server‑side request forgery (CWE‑918) can expose internal services, retrieve sensitive data, or trigger unintended actions, all from a remote input without needing authentication.
Affected Systems
The vulnerability affects the Deno Backend component of NonceGeek dim‑sum‑app, specifically the deno/main.tsx file. Any deployment that has not applied the patch identified by commit 8389032e5d52c28c4855c6126ca7d0eae8af346a remains vulnerable; explicit version numbers are not provided, so all unpatched instances are at risk.
Risk and Exploitability
With a CVSS score of 6.9 the issue is classified as moderate. Although the EPSS score is not released, the public disclosure and availability of an exploit indicate a realistic chance of use. The flaw is exploitable remotely and does not require any special privileges, making it a significant concern for exposed services.
OpenCVE Enrichment