CVE-2026-56769 Details
Description
Huly Platform through 0.7.423, fixed in commit 68cbf8a contains an authenticated server-side request forgery vulnerability in the /import endpoint of front pod that allows workspace users to make arbitrary server requests. Attackers can exploit this by supplying malicious URLs to fetch internal services, exfiltrate responses, and replay credentials against backend systems.
A server-side request forgery (SSRF) vulnerability has been identified in the Huly Platform, affecting versions through 0.7.423. The vulnerability resides in the front pod's '/import' endpoint, where authenticated workspace users can make arbitrary server requests. There is no URL allowlist or host validation, allowing users to fetch internal services, exfiltrate responses, and replay credentials against backend systems that share the front pod's network. The vulnerability was introduced in a deprecated endpoint that lacks proper SSRF defenses, in contrast to other pods that have implemented necessary safeguards.
Users can update to Huly Platform version 0.7.423 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 25, 2026CISA-ADP
Assessed Jun 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/hcengineering/platform/commit/68cbf8a88642d8313f151a274fb5c24dee6a2762 | [email protected] | Source CodeVendor |
| https://github.com/hcengineering/platform/issues/10892 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/hcengineering/platform/pull/10910 | [email protected] | Source CodeVendor |
| https://www.vulncheck.com/advisories/huly-platform-server-side-request-forgery-via-import-endpoint | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Huly Platform | <= 0.7.423 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 14, 2026 | CVE Modified | [email protected] |
| Jun 25, 2026 | New CVE Received | [email protected] |
| Jun 25, 2026 | CVE Modified | CISA-ADP |
Volerion