Junglewise Threat Intelligence

CVE-2024-13971: Lobster DATA Lobster_pro XXE in XML parser

CVE-2024-13971 · Severity: high · CVSS 7.5 · Published 2026-04-30

Executive brief

Lobster_pro is a no-code platform used for business process automation and data integration. A security flaw in how the system handles data files allows unauthenticated attackers to remotely read sensitive files from the server and its connected network shares. This could lead to the exposure of corporate secrets, credentials, or internal network information, potentially facilitating further attacks on the organization's infrastructure.

Technical details

An XML External Entity (XXE) vulnerability exists in Lobster_pro due to improper restriction of XML external entity references (CWE-611) within its XML parser. The vulnerability is located at the '/system/web' endpoint, which processes XML via HTTP POST requests. An unauthenticated remote attacker can submit a crafted XML payload containing external entity references to trigger the vulnerability. Successful exploitation allows the attacker to read arbitrary files from the local filesystem and adjacent SMB shares, perform Server-Side Request Forgery (SSRF) via HTTP GET requests, and potentially leak NTLM hashes via the SMB protocol. The vulnerability is fixed in version 4.12.6-GA.

Affected products

  • Lobster DATA GmbH Lobster_pro versions prior to 4.12.6-GA

Timeline

  • 2024-08-12: other: Initial contact with vendor
  • 2024-08-14: other: Vulnerability reported to vendor
  • 2024-09-19: patched: Vulnerability reported fixed by vendor in Lobster_pro release 4.12.6-GA
  • 2025-07-03: other: CVE ID reserved
  • 2026-04-30: advisory: Public advisory released

References