CVE-2026-72846 | Lightdash up to 1.146.3 Webhook Delivery GoogleChatClient.ts sendWebhook webhook server-side request forgery

SecurityVulns

A vulnerability was found in Lightdash up to 1.146.3. It has been rated as critical. Affected is the function sendWebhook of the file packages/backend/src/clients/GoogleChat/GoogleChatClient.ts of the component Webhook Delivery. The manipulation of the argument webhook leads to server-side request forgery.

This vulnerability is listed as CVE-2026-72846. The attack may be initiated remotely. There is no available exploit.

Upgrading the affected component is advised.VulDB Recent EntriesRead More