CVE-2026-9372 Details
Description
A flaw has been found in ItzCrazyKns Vane up to 1.12.1. This vulnerability affects unknown code of the file src/app/api/providers/route.ts of the component Model Provider API. This manipulation of the argument baseURL causes server-side request forgery. Remote exploitation of the attack is possible. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
A server-side request forgery (SSRF) vulnerability has been identified in ItzCrazyKns Vane versions through 1.12.1. The issue arises in the Model Provider API, specifically within the 'src/app/api/providers/route.ts' file. The vulnerability allows remote exploitation by manipulating the 'baseURL' argument, enabling the server to make unauthorized HTTP requests to internal or external destinations. This flaw was reported to the project, but no response has been received yet.
To address this vulnerability, it is recommended to add authentication to the '/api/providers' endpoint, implement URL validation to restrict accepted URLs and block private/internal IP addresses, sanitize error messages to prevent information leakage, and consider network-level isolation to prevent access to sensitive internal services or metadata endpoints.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 24, 2026CISA-ADP
Assessed May 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/ItzCrazyKns/Vane/ | [email protected] | ProductVendor |
| https://github.com/ItzCrazyKns/Vane/issues/1124 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://vuldb.com/submit/813211 | [email protected] | Permission Required |
| https://vuldb.com/vuln/365336 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/365336/cti | [email protected] | AdvisoryPermission Required |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ItzCrazyKns Vane | <= 1.12.1 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 24, 2026 | New CVE Received | [email protected] |
Volerion