Executive brief
Libredesk is a self-hosted customer support application. A reported issue regarding the ability of administrators to configure webhooks to arbitrary internal destinations has been dismissed by the maintainers as intended functionality. Because the feature requires administrative privileges that already grant full control over the application, it does not represent a security vulnerability in the context of this single-tenant software.
Technical details
This CVE was originally filed as a Server-Side Request Forgery (SSRF) vulnerability (CWE-918) in Libredesk's webhook configuration. The maintainer subsequently rejected the report, clarifying that Libredesk is a single-tenant application where the 'Application Admin' permission required to configure webhooks is not granted by default and implies full administrative control. Since the documented purpose of the feature is to send outbound HTTP requests to operator-chosen URLs, the ability to reach internal destinations via this admin-only feature is considered 'working as designed.' The CVE has been officially revoked.
Affected products
- Libredesk Libredesk Prior to 1.0.2-0.20260215211005-727213631ce6
Timeline
- 2026-02-19: disclosed: Initial CVE entry created by GitHub
- 2026-06-09: other: CVE rejected by maintainer/GitHub as intended behavior