CVE-2026-3681 Details
Description
A weakness has been identified in welovemedia FFmate up to 2.0.15. This affects the function fireWebhook of the file /internal/service/webhook/webhook.go. Executing a manipulation can lead to server-side request forgery. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
A server-side request forgery (SSRF) vulnerability has been identified in welovemedia FFmate versions through 2.0.15. The issue arises in the webhook functionality, where user-controlled URLs are used to initiate HTTP requests without proper validation. This vulnerability allows attackers to direct webhook requests to internal resources, potentially probing network services, accessing restricted metadata endpoints, bypassing firewall rules, scanning internal ports, and exfiltrating sensitive data from otherwise inaccessible services.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Mar 7, 2026CISA-ADP
Assessed Mar 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/CC-T-454455/Vulnerabilities/tree/master/ffmate/vulnerability-1 | [email protected] | ExploitTechnical Analysis |
| https://vuldb.com/?ctiid.349583 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/?id.349583 | [email protected] | AdvisoryExploitPartial Content |
| https://vuldb.com/?submit.765558 | [email protected] | Technical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| welovemedia FFmate | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Mar 7, 2026 | New CVE Received | [email protected] |
Volerion