Junglewise Threat Intelligence

CVE-2023-46945: QD-Today QD SSRF in OCR verification code function

CVE-2023-46945 · Severity: critical · CVSS 9.1 · Published 2026-04-08

Technologies: Qd-Today Qd. Vendors: Qd-Today.

Executive brief

QD, an open-source HTTP task automation framework, contains a security flaw in its image processing component. An attacker can trick the server into making unauthorized requests to internal or external systems by providing a malicious URL for a verification code image. This could allow an attacker to bypass firewalls, access sensitive internal data, or scan private corporate networks.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the QD HTTP task automation framework (versions 20220208 through 20230821). The vulnerability is located in the OCR (Optical Character Recognition) functionality, where the application fails to properly validate user-supplied URLs for verification code images. A remote, unauthenticated attacker can provide a crafted URL, causing the Tornado-based server to initiate outbound HTTP requests. This can be leveraged to access internal metadata services, scan internal network ports, or interact with other internal services that are not exposed to the public internet.

Affected products

  • QD-Today QD 20220208 through 20230821

Timeline

  • 2023-11-23: other: Researcher activity on Gist advisory
  • 2026-04-08: disclosed: CVE published

References