Executive brief
A security vulnerability has been identified in linqi's custom process creation feature, which is used to automate business workflows. An authorized user can exploit this flaw to force the server to communicate with internal systems that are normally protected from the outside internet. This could allow an attacker to map out your internal network and identify other vulnerable systems or services.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in the custom process creation feature of linqi. The flaw is located in the HTTP Request component, which fails to properly validate or restrict the destination of outgoing requests. An authenticated attacker can craft a process that forces the server to send arbitrary HTTP requests to internal network addresses. By analyzing the application's responses—such as success messages, failures, or 504 Gateway Time-outs—the attacker can perform port scanning and internal network reconnaissance. This vulnerability is tracked as CWE-918.
Affected products
- linqi linqi
Timeline
- 2026-06-05: disclosed
- 2026-06-05: advisory