Description
SwaggerUI supports displaying remote OpenAPI definitions through the ?url parameter. This enables robust demonstration capabilities on sites like petstore.swagger.io, editor.swagger.io, and similar sites, where users often want to see what their OpenAPI definitions would look like rendered.
Recommendation
Update the swagger-ui-dist package to the latest compatible version. Followings are version details:
- Affected version(s): < 4.1.3
- Patched version(s): 4.1.3
References
Could your website be exposed too?
SmartScanner can check your website for Server side request forgery in SwaggerUI - swagger-ui-dist and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Server side request forgery in SwaggerUI - swagger-ui-react - Vulnerability
- Server side request forgery in SwaggerUI - Vulnerability
- Nuxt OG Image vulnerable to Server-Side Request Forgery via user-controlled parameters - Vulnerability
- Nu Html Checker (vnu) contains a Server-Side Request Forgery (SSRF) vulnerability - CVE-2025-15104


