{"id":"CVE-2026-92568","published":"2026-09-16T15:19:02.453","lastModified":"2026-09-16T16:17:23.393","description":"MLRun through 1.11.0 contains a server-side request forgery vulnerability in the WebhookNotification handler that allows authenticated users to make the API server send arbitrary HTTP requests to internal addresses. Attackers can update a run with a malicious webhook notification that executes when the run reaches a terminal state, enabling requests to internal services, Kubernetes APIs, or cloud metadata endpoints from within the cluster.","cvssScore":5.4,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","cwes":["CWE-918"],"vendors":[],"products":[],"references":[{"url":"https://github.com/mlrun/mlrun","tags":[]},{"url":"https://github.com/mlrun/mlrun/blob/6007f29e8b1ca976ea632e8714a312df50cb13e7/mlrun/utils/notifications/notification/webhook.py#L33-L94","tags":[]},{"url":"https://github.com/mlrun/mlrun/issues/10041","tags":[]},{"url":"https://www.vulncheck.com/advisories/mlrun-through-1.11.0-server-side-request-forgery-via-webhook","tags":[]},{"url":"https://github.com/mlrun/mlrun/issues/10041","tags":[]}],"exploitRefs":[{"url":"https://github.com/mlrun/mlrun","tags":[]},{"url":"https://github.com/mlrun/mlrun/blob/6007f29e8b1ca976ea632e8714a312df50cb13e7/mlrun/utils/notifications/notification/webhook.py#L33-L94","tags":[]},{"url":"https://github.com/mlrun/mlrun/issues/10041","tags":[]},{"url":"https://github.com/mlrun/mlrun/issues/10041","tags":[]}],"hasPoc":true,"ai":null}