CVE-2026-88892 | Openpanel-dev OpenPanel Data Import umami.ts parseRemoteFile config.fileUrl server-side request forgery

SecurityVulns

A vulnerability marked as critical has been reported in Openpanel-dev OpenPanel. Affected is the function parseRemoteFile of the file packages/importer/src/providers/umami.ts of the component Data Import. This manipulation of the argument config.fileUrl causes server-side request forgery.

The identification of this vulnerability is CVE-2026-88892. It is possible to initiate the attack remotely. There is no exploit available.VulDB Recent EntriesRead More