CVE-2026-108523 | Studio-Saelix Sencho up to 0.94.1 git-sources Browse API Endpoint outboundTarget.ts repo_url server-side request forgery

SecurityVulns

A vulnerability labeled as problematic has been found in Studio-Saelix Sencho up to 0.94.1. This vulnerability affects unknown code of the file outboundTarget.ts of the component git-sources Browse API Endpoint. Executing a manipulation of the argument repo_url can lead to server-side request forgery.

This vulnerability appears as CVE-2026-108523. The attack may be performed from remote. In addition, an exploit is available.

The presence of this vulnerability remains uncertain at this time.

It is advisable to implement a patch to correct this issue.

The vendor explains: “Git repository access is an intentional, privileged administrative function. Sencho explicitly supports repositories hosted on private LAN, VPC, VPN, CGNAT, and IPv6 ULA networks. The report does not demonstrate a privilege-boundary bypass or access by an unprivileged user. We therefore dispute the CVE characterization of this behavior. As defense in depth, we have nevertheless hardened repository access. Git HTTPS and SSH connections now validate and pin DNS resolution, reject loopback, link-local, multicast, selected special-use and metadata targets, disable redirects and inherited proxy routing, and retain strict SSH host-key verification.”VulDB Recent EntriesRead More