---
id: CVE-2026-63769
title: >-
  Huginn before 2026.09.09 contains a server-side request forgery vulnerability
  in the fetch_url method of ScenarioImport that allows authenticated users to
  make arbitrary HTTP requests by submitting crafted URLs
summary: >-
  Huginn before 2026.09.09 contains a server-side request forgery vulnerability
  in the fetch_url method of ScenarioImport that allows authenticated users to
  make arbitrary HTTP requests by submitting crafted URLs. Attackers can probe
  inter…
severity: high
cvss: 7.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'
cwe:
  - CWE-918
vendor: huginn
product: huginn
affected:
  - huginn < 2026.09.09
published: '2026-07-20'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T20:16:48.943'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-63769'
references:
  - url: 'https://github.com/huginn/huginn/issues/3679'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/huginn/huginn/pull/3684'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/huginn/huginn/releases/tag/v2026.09.09'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/huginn/huginn/security/advisories/GHSA-f7cq-gj98-cfjp'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/huginn-ssrf-via-scenarioimport-fetch-url-method
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.00415
epssPercentile: 0.33133
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-07-21T13:38:57.178580Z'
ingestedAt: '2026-09-14T20:14:21.162Z'
---

## Overview

Huginn before 2026.09.09 contains a server-side request forgery vulnerability in the fetch_url method of ScenarioImport that allows authenticated users to make arbitrary HTTP requests by submitting crafted URLs. Attackers can probe internal network services, enumerate ports via error signatures, and access cloud metadata endpoints to retrieve sensitive credentials.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
