CVE-2026-102244 Details
Description
A security flaw has been discovered in MODSetter SurfSense up to 0.0.36. Impacted is an unknown function of the file surfsense_backend/app/routes/editor_routes.py of the component Document Export Feature. Performing a manipulation results in server-side request forgery. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 0.0.36.3 is recommended to address this issue. The patch is named 2faff7b3823322a9cb6797973e6caf089386c354. The affected component should be upgraded.
A server-side request forgery (SSRF) vulnerability has been identified in MODSetter SurfSense versions through 0.0.36. The issue resides in the document export feature of the FastAPI backend, specifically within the file 'surfsense_backend/app/routes/editor_routes.py'. This vulnerability allows authenticated users to manipulate exported Markdown documents to include 'file://' URIs, which the server-side process then fetches and inlines as 'data:' URIs in the exported HTML. This exploitation can lead to unauthorized access to local files on the server.
Users are advised to upgrade to SurfSense version 0.0.36.3, where this vulnerability has been patched. Instructions for downloading the latest version are available on the SurfSense GitHub repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 29, 2026CISA-ADP
Assessed Sep 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gist.github.com/DReazer/57126e711507324a547edde96c62c218 | [email protected] | ExploitRemedy |
| https://github.com/MODSetter/SurfSense/ | [email protected] | Vendor |
| https://github.com/MODSetter/SurfSense/commit/2faff7b3823322a9cb6797973e6caf089386c354 | [email protected] | Source CodeVendor |
| https://github.com/MODSetter/SurfSense/releases/tag/0.0.36.3 | [email protected] | Release NotesVendor |
| https://vuldb.com/cve/CVE-2026-102244 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/933330 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/411142 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/411142/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| MODSetter SurfSense | 0.0.36 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 29, 2026 | CVE Modified | CISA-ADP |
| Sep 29, 2026 | New CVE Received | [email protected] |
Volerion