Executive brief
Huly Platform is an all-in-one project management and collaboration tool. The platform's print service lacks proper validation of URLs supplied by authenticated users, allowing them to download and render content from internal network services. An attacker with workspace access could exploit this to retrieve sensitive data from metadata services or other internal systems, potentially exposing confidential configuration, credentials, or internal service details.
Technical details
A server-side request forgery (SSRF) vulnerability exists in the print service endpoint due to missing hostname allowlist validation. The service uses Puppeteer to render arbitrary URLs provided by authenticated workspace members into PDF or image files. Although an ALLOWED_HOSTNAMES configuration parameter exists, the implementation fails to enforce it against user-supplied URLs. Exploitation requires workspace authentication but no additional privilege escalation. An attacker can reach internal metadata services, cloud provider endpoints (AWS/GCP metadata servers), and network-accessible hosts to exfiltrate sensitive data or perform reconnaissance.
Affected products
- Huly Platform through 0.7.426
Timeline
- 2026-09-14: disclosed