WhisperX tag archive

#CWE-918

This page collects WhisperX intelligence signals tagged #CWE-918. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (2)

The Lab · 2026-04-16 04:22:40 · GitHub Issues

1. GitHub Codebase Exposed: High-Risk SSRF Vulnerability (CWE-918) Threatens Private Organization Data

A critical server-side request forgery (SSRF) vulnerability has been flagged within a GitHub-hosted codebase, posing a direct threat to private organizational data. The vulnerability, classified as HIGH severity, stems from a dangerous pattern where untrusted data from a user request object is passed directly into a ne...

The Lab · 2026-04-21 00:22:46 · GitHub Issues

2. HIGH-Severity SSRF Flaw Persists in Workspace-Server Despite Partial Timeout Fix

A critical Server-Side Request Forgery (SSRF) vulnerability remains unpatched in the workspace-server codebase, despite a recent pull request that only implemented a superficial timeout. The core security flaw—a complete lack of URL validation before making outbound HTTP requests—leaves internal systems exposed to pote...