Junglewise Threat Intelligence

CVE-2026-63769: Huginn SSRF in ScenarioImport fetch_url method

CVE-2026-63769 · Severity: high · CVSS 7.7 · Published 2026-07-20

Executive brief

Huginn, an open-source system for building automated agents, is vulnerable to a security flaw in its scenario import feature. An authenticated user can trick the server into making unauthorized requests to internal network services that are not normally accessible from the internet. This could allow an attacker to scan private networks, access sensitive internal data, or steal cloud service credentials, potentially leading to a broader breach of the hosting environment.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the `fetch_url` method of the `ScenarioImport` class in Huginn. The application uses a weak regular expression (`/\Ahttps?:\/\//i`) to validate user-supplied URLs before fetching them with the Faraday library. Because the validation does not restrict target hosts, authenticated users can submit URLs pointing to loopback addresses, internal RFC 1918 IP ranges, or cloud metadata endpoints (e.g., AWS IMDS). Attackers can distinguish between open and closed ports based on specific error signatures returned by the server (e.g., `Errno::ECONNREFUSED` vs protocol handshake leaks). A pull request (PR #3684) has been proposed to implement safe URL fetching with host validation and redirect limits.

Affected products

  • Huginn Huginn through 2022.08.18

Timeline

  • 2026-05-22: disclosed: Private disclosure to maintainers
  • 2026-06-30: other: Public issue opened on GitHub
  • 2026-07-06: other: Fix proposed via pull request #3684
  • 2026-07-20: advisory: CVE published and NVD record created

References