Junglewise Threat Intelligence

CVE-2026-63107: LimeSurvey SSRF in REST API survey template endpoint

CVE-2026-63107 · Severity: high · CVSS 7.7 · Published 2026-07-20

Technologies: LimeSurvey. Vendors: LimeSurvey.

Executive brief

LimeSurvey, a popular open-source survey tool, contains a security flaw in its programming interface (API) used for managing survey templates. An authorized user can trick the server into making unauthorized connections to internal systems or cloud management services. This could allow an attacker to steal sensitive data, such as cloud access tokens or information from other private servers, that are not normally accessible from the internet.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the `getTemplateData()` function within `application/libraries/Api/Command/V1/SurveyTemplate.php`. The application unsafely uses the HTTP 'Host' header to construct a URL for a server-side cURL request intended to render survey previews. An authenticated attacker with survey 'read' permissions can manipulate the Host header to force the server to perform GET requests against arbitrary internal or external targets. Because the application disables TLS verification (CURLOPT_SSL_VERIFYPEER/HOST) and returns the full response body, attackers can exfiltrate sensitive data from internal services or cloud metadata endpoints (e.g., IMDSv2).

Affected products

  • LimeSurvey LimeSurvey <= 6.17.10, <= 7.0.4

Timeline

  • 2026-07-20: disclosed
  • 2026-07-20: advisory

References

Related threats