Tag
#SSRF
The Map and the Window: How an Agentic Scan Chained a Documentation Leak Into Stolen Credentials
See how Ostorlab's Agentic Deep Scan chained a Medium-severity OpenAPI disclosure and an SSRF vulnerability to bypass a loopback restriction and extract database credentials.
Sep 23, 2026
Breaking Down the Latest Version of GoPhish: Source-Code Assessment with Ostorlab Agentic Deep Scan
A technical assessment of the latest version of GoPhish that examines how the platform handles tr...
Jul 16, 2026
CVE-2026-5205: Critical SSRF in Chatwoot Uploads
A deep dive into a critical Server-Side Request Forgery (SSRF) vulnerability in Chatwoot's upload...
Apr 29, 2026
Roundcube IMAP Command Injection and SSRF Flaws
A deep dive into two critical vulnerabilities uncovered in Roundcube Webmail (< 1.6.14, 1.5.14, 1...
Apr 08, 2026
More tagged #SSRF
CVE-2026-26019 : LangChain RecursiveUrlLoader Server-Side Request Forgery Vulnerability
A technical breakdown of CVE-2026-26019, a CVSS 4.1 medium Server-Side Request Forgery vulnerability in the LangChain Community JavaScript package (< 1.1.14). The RecursiveUrlLoader class uses a naive string prefix check to validate crawled URLs, allowing an attacker to bypass the default preventOutside restriction with a suffixed domain and redirect the crawler to internal network assets, potentially exposing sensitive credentials and metadata endpoints.
Mar 04, 2026