Vulnerabilities/

Strapi allows Server-Side Request Forgery in Webhook function

Severity:
Medium

Description

In Strapi latest version, at function Settings -> Webhooks, the application allows us to input a URL in order to create a Webook connection. However, we can input into this field the local domains such as localhost, 127.0.0.1, 0.0.0.0,….

Recommendation

Update the @strapi/admin package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@strapi/admin
Anything's wrong? Let us know Last updated on May 29, 2025

This issue is available in SmartScanner Professional

See Pricing