Executive brief
A security vulnerability has been found in the Huly Platform, an open-source workflow and project management tool. An attacker can trick the system into making unauthorized network requests to internal or external servers. This could allow an attacker to access sensitive internal data or bypass security controls that protect private infrastructure.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in hcengineering Huly Platform version 0.7.382. The flaw is located within the 'Import Endpoint' component, specifically in the file 'server/front/src/index.ts'. A remote attacker with low privileges can exploit this by sending a crafted request that forces the server to perform unintended network actions. This can be used to scan internal networks, access metadata services, or interact with other internal systems that are not exposed to the public internet. A public exploit (PoC) is reportedly available, and the vendor has not yet provided a patch or official response.
Affected products
- hcengineering Huly Platform 0.7.382
Timeline
- 2026-04-06: disclosed
- 2026-04-06: advisory: NVD published the CVE record