Executive brief
ZenTao is a project management platform that includes an AI module for model testing. A vulnerability in the AI model connection testing function allows attackers to make arbitrary network requests from the server, potentially exposing internal systems and sensitive data. An attacker can craft a malicious request to redirect the server to access internal resources or external systems without authorization.
Technical details
A server-side request forgery (SSRF) vulnerability exists in the makeRequest function of the ZenTao AI module (module/ai/model.php), specifically in the modelTestConnection functionality. The vulnerability is triggered through manipulation of the "Base" argument, which is not properly validated before being used in network requests. An attacker can exploit this via a remote network request without requiring authentication. The flaw allows an attacker to make the ZenTao server perform arbitrary HTTP requests to internal or external systems, potentially accessing restricted resources, services, or metadata. Upgrading to version 21.7.6 or later mitigates this issue.
Affected products
- ZenTao ZenTao up to 21.7.6-8564
Timeline
- 2025-11-30: disclosed