Executive brief
Hemmelig is an open-source secret-sharing application that allows users to create and share encrypted messages. The Secret Requests feature includes a webhook URL validation mechanism designed to prevent attackers from targeting internal network resources. However, this filter can be bypassed using DNS rebinding or open redirect techniques, allowing authenticated users to trigger server-side requests to private network addresses. While the information returned is limited (blind SSRF), attackers can infer port availability through response-timing techniques.
Technical details
The vulnerability is a Server-Side Request Forgery (SSRF) filter bypass in the isPublicUrl function (/api/lib/utils.ts). The function validates webhook URLs using only hostname string matching against a blocklist of private IP patterns, without resolving the hostname to its actual IP address. Attackers can bypass this using two methods: (1) DNS rebinding to domains like localtest.me that resolve to 127.0.0.1, and (2) open redirect services like httpbin.org/redirect-to that accept an internal URL as a parameter. The vulnerability requires authentication and allows making blind HTTP requests to internal resources; while responses cannot be exfiltrated, timing analysis can infer port status. The fix involves resolving hostnames to IPs before validation and disabling automatic redirect following in the webhook fetch logic. Patched in version 7.3.3.
Affected products
- HemmeligOrg Hemmelig <=7.3.2
Timeline
- 2025-12-29: disclosed
- 2025-12-29: patched: Fixed in version 7.3.3