๐Ÿ” CVE Alert

CVE-2026-77066

MEDIUM 5.0

Omnivore Server-Side Request Forgery via the scanFeeds GraphQL Query

CVSS Score
5.0
EPSS Score
0.0%
EPSS Percentile
0th

The scanFeedsResolver in packages/api/src/resolvers/subscriptions/index.ts passes the caller-supplied url straight to axios.get(url, rssParserConfig()) with no address validation. The same file guards the subscribe path with validateUrl(), which rejects private and reserved ranges through the private-ip library, and createPageSaveRequest applies the same check, so the omission is specific to this resolver. An authenticated user can direct the server to request arbitrary internal endpoints. The response is parsed as a feed or as HTML and the resolver returns the resulting url, title, description and type fields, so disclosure is limited to feed-shaped metadata and to link elements advertising RSS or Atom feeds; requests that do not parse still distinguish reachable ports from unreachable ones through the resulting error.

CWE CWE-918
Vendor omnivore-app
Product omnivore
Published Aug 20, 2026
Stay Ahead of the Next One

Get instant alerts for omnivore-app omnivore

Be the first to know when new medium vulnerabilities affecting omnivore-app omnivore are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
Low
Integrity
None
Availability
None

Affected Versions

omnivore-app / omnivore
0 < c4d7d8562e6b9aabb1d8e4dabca268e314baa43a

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/omnivore-app/omnivore/issues/4647 github.com: https://github.com/omnivore-app/omnivore/commit/c4d7d8562e6b9aabb1d8e4dabca268e314baa43a github.com: https://github.com/omnivore-app/omnivore/blob/0d66408746788e07cec43928581b2567308ab575/packages/api/src/resolvers/subscriptions/index.ts#L445 github.com: https://github.com/omnivore-app/omnivore vulncheck.com: https://www.vulncheck.com/advisories/omnivore-server-side-request-forgery-via-the-scanfeeds-graphql-query

Credits

๐Ÿ” geo-chen