Junglewise Threat Intelligence

CVE-2026-76795: AeternaLabsHQ PullMD server-side request forgery in REST API

CVE-2026-76795 · Severity: high · CVSS 7.3 · Published 2026-08-20

Executive brief

PullMD is a self-hosted service that converts web pages, documents, and other content into Markdown format via a REST API. A server-side request forgery (SSRF) vulnerability in the /api endpoint allows attackers to make arbitrary HTTP requests from the server, potentially to access internal systems, cloud metadata services, or private networks that the server can reach.

Technical details

The vulnerability is a server-side request forgery (SSRF) flaw in the REST API endpoint that handles the url parameter. An attacker can manipulate the url argument to trigger the server to make HTTP requests to arbitrary destinations, including private IP ranges, localhost, link-local addresses, CGNAT ranges, and cloud metadata endpoints. The attack is remotely exploitable without requiring authentication. An attacker can leverage this to access internal services, retrieve sensitive metadata, or interact with systems on the private network. The fix, released in version 3.3.0 (commit 96448894cc93ccecb0bdcbf263a9d25390a8455e), implements default-deny restrictions on requests to private, loopback, and metadata address ranges, with an optional allowlist configuration.

Affected products

  • AeternaLabsHQ PullMD 3.2.0

Timeline

  • 2026-08-20: disclosed
  • 2026-07-08: patched: Fixed in version 3.3.0

References