๐Ÿ” CVE Alert

CVE-2026-108523

MEDIUM 4.3

Studio-Saelix Sencho git-sources Browse API Endpoint outboundTarget.ts server-side request forgery

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability was determined in Studio-Saelix Sencho up to 0.94.1. This vulnerability affects unknown code of the file outboundTarget.ts of the component git-sources Browse API Endpoint. Executing a manipulation of the argument repo_url can lead to server-side request forgery. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The presence of this vulnerability remains uncertain at this time. This patch is called 79b86ddcd4aefdd6941f098e35990ab397b13c72. It is advisable to implement a patch to correct this issue. The vendor explains: "Git repository access is an intentional, privileged administrative function. Sencho explicitly supports repositories hosted on private LAN, VPC, VPN, CGNAT, and IPv6 ULA networks. The report does not demonstrate a privilege-boundary bypass or access by an unprivileged user. We therefore dispute the CVE characterization of this behavior. As defense in depth, we have nevertheless hardened repository access. Git HTTPS and SSH connections now validate and pin DNS resolution, reject loopback, link-local, multicast, selected special-use and metadata targets, disable redirects and inherited proxy routing, and retain strict SSH host-key verification."

CWE CWE-918
Vendor studio-saelix
Product sencho
Published Oct 11, 2026
Stay Ahead of the Next One

Get instant alerts for studio-saelix sencho

Be the first to know when new medium vulnerabilities affecting studio-saelix sencho are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Studio-Saelix / Sencho
0.94.0 0.94.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/416189 vuldb.com: https://vuldb.com/vuln/416189/cti vuldb.com: https://vuldb.com/cve/CVE-2026-108523 vuldb.com: https://vuldb.com/submit/893367 gist.github.com: https://gist.github.com/jovair1994/93446c14d30a16313e830490d71bbd1d github.com: https://github.com/Studio-Saelix/sencho/pull/1877 github.com: https://github.com/Studio-Saelix/sencho/commit/79b86ddcd4aefdd6941f098e35990ab397b13c72 github.com: https://github.com/Studio-Saelix/sencho/

Credits

๐Ÿ” jpazz (VulDB User) VulDB CNA Team