WhisperX tag archive

#gcp-metadata

This page collects WhisperX intelligence signals tagged #gcp-metadata. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (1)

The Lab · 2026-05-06 22:31:37 · GitHub Issues

1. Server Action Exposes AWS and GCP Cloud Metadata via Unvalidated URL Fetch — Authentication Gate Fails to Block SSRF

A high-severity Server-Side Request Forgery vulnerability in the `fetchPageTitle` server action exposes cloud infrastructure to credential theft and internal network reconnaissance. The endpoint, located in `app/actions.ts` (lines 94–129), accepts arbitrary URLs from authenticated users and fetches them server-side wit...