Executive brief
EspoCRM is an open-source Customer Relationship Management (CRM) platform used by businesses to manage customer data and interactions. A security flaw in the attachment upload feature allows authenticated users to bypass security restrictions and force the server to communicate with internal network services. This could allow an attacker to map out a company's private internal network, identify hidden services, or interact with internal systems that are not intended to be accessible from the internet.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in the POST /api/v1/Attachment/fromImageUrl endpoint of EspoCRM. The vulnerability is caused by a Time-of-Check Time-of-Use (TOCTOU) flaw where the application validates a hostname using dns_get_record() but performs the actual HTTP request using curl's internal resolver. An attacker can use DNS rebinding to provide a public IP during validation and an internal IP during the connection phase. Additionally, the HostCheck::isNotInternalHost() function fails closed by implicitly allowing hosts if DNS resolution returns no records. Authenticated attackers can exploit this to scan internal ports and interact with internal HTTP services. The issue is fixed in version 9.3.4 by ensuring validation occurs against the primary IP address resolved by curl.
Affected products
- EspoCRM EspoCRM <= 9.3.3
Timeline
- 2026-03-24: patched: Version 9.3.4 released
- 2026-04-13: advisory: GitHub Security Advisory published
- 2026-04-13: disclosed: CVE-2026-33659 published