Executive brief
OttoKit is a WordPress plugin that facilitates web automation and integration workflows. An unauthenticated attacker can exploit a server-side request forgery vulnerability to make the affected server connect to internal systems and leak sensitive data from behind firewalls, potentially compromising internal infrastructure and confidential information.
Technical details
The vulnerability is a classic Server-Side Request Forgery (SSRF) flaw in OttoKit versions 1.1.35 and earlier that allows unauthenticated attackers to craft malicious requests. The flaw permits attackers to make the server perform outbound connections to arbitrary internal or external systems, bypassing network access controls. This can be leveraged to probe internal services, exfiltrate data, or attack internal systems that are not directly accessible from the internet. The vulnerability requires no authentication and is network-reachable. A patch is available in version 1.1.36 and later.
Affected products
- Brainstorm Force OttoKit <=1.1.35
Timeline
- 2026-08-18: disclosed: CVE published
- 2026-08-14: other: Vulnerability reported to Patchstack
- 2026-08-14: patched: Patch released in version 1.1.36