Executive brief
Pentestify, a penetration testing reporting tool, contains a vulnerability in its PDF generation feature. An attacker can trick the server into making unauthorized requests to internal systems or cloud metadata services. This could allow an attacker to view sensitive internal information or gain access to cloud credentials, potentially compromising the entire hosting environment.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in the GET /api/reports/{id}/pdf endpoint within backend/main.py. The application constructs the target URL for PDF rendering using the 'request.base_url' value without proper validation or sanitization. By providing a crafted Host header, a remote attacker can force the server's headless browser to fetch and render content from arbitrary internal or external URLs, including cloud metadata services (e.g., IMDSv2). Additionally, the vulnerability can be triggered via malicious image sources in client logos or finding evidence. The issue is addressed in version 1.1.0 by validating image sources and sanitizing report data.
Affected products
- ccyl13 Pentestify <= 1.0.0
Timeline
- 2026-06-23: patched: Fix committed in version 1.1.0
- 2026-06-24: disclosed: CVE-2026-13150 published