Executive brief
Appsmith is a platform used by businesses to build internal admin panels and dashboards. A security flaw in the email configuration tool allows an administrator to bypass internal security filters and probe the company's private network. This could lead to the discovery of sensitive internal services, such as databases or cloud metadata services, which are normally hidden from the internet.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in the 'POST /api/v1/admin/send-test-email' endpoint of Appsmith Server. The application uses JavaMail to establish raw TCP connections to user-supplied 'smtpHost' and 'smtpPort' values without IP validation, effectively bypassing the 'WebClientUtils.IP_CHECK_FILTER' which only applies to HTTP requests. Furthermore, the application returns raw 'MailException' error messages in the API response. An attacker with high privileges (admin) can exploit this to perform error-based port scanning and service banner enumeration of the internal network, including reaching loopback addresses and cloud metadata services (e.g., 169.254.169.254). The issue is resolved in version 1.99.
Affected products
- Appsmith Appsmith Server < 1.99
Timeline
- 2026-04-17: disclosed: Advisory published on GitHub
- 2026-06-24: advisory: NVD publication date
- 1.99: patched