CVE-2026-77067 | omnivore-app Omnivore Webhook Resolver index.ts setWebhookResolver url server-side request forgery
A vulnerability, which was classified as critical, has been found in omnivore-app Omnivore. The impacted element is the function setWebhookResolver of the file packages/api/src/resolvers/webhooks/index.ts of the component Webhook Resolver. The manipulation of the argument url leads to server-side request forgery.
This vulnerability is listed as CVE-2026-77067. The attack may be initiated remotely. There is no available exploit.
Applying a patch is the recommended action to fix this issue.VulDB Recent EntriesRead More