Executive brief
Nitter, an alternative front-end for Twitter/X, contains a security flaw in its video processing component. This vulnerability allows unauthorized individuals to use the Nitter server as a proxy to access private internal networks or cloud management services. This could lead to the exposure of sensitive internal data or administrative credentials, potentially compromising the entire server infrastructure.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in Nitter's `/video` media proxy endpoint due to a failure to validate target URLs against authorized Twitter/X domains. While the `/pic` endpoint correctly implements domain validation, the `/video` route only checks for the presence of the 'http' substring. Furthermore, the endpoint relies on an HMAC signature for security that uses a hardcoded default key ('secretkey') found in the configuration templates. An unauthenticated remote attacker can calculate valid HMACs for arbitrary URLs, allowing them to force the server to fetch and return content from internal network resources or cloud metadata services (e.g., IMDS). The issue was addressed in commit 44b2f09 by enforcing domain validation and warning users about the default HMAC key.
Affected products
- zedeus Nitter versions prior to commit 44b2f096f67da2cc257a0e262a94a7ae79e95d47
Timeline
- 2026-06-13: disclosed: Issue reported on GitHub by researcher George Chen
- 2026-06-18: patched: Fix committed to master branch
- 2026-06-29: advisory: CVE published and NVD record created