Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 29 Sep 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ClaraVerse through 0.3.1 contains server-side request forgery protection bypasses in the download_file and scrape_web agent tools. Authenticated users can bypass hostname validation and IPv6 transition address filtering to make the server request internal services and cloud instance metadata endpoints. | |
| Title | ClaraVerse through 0.3.1 SSRF Protection Bypass | |
| Weaknesses | CWE-918 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-29T20:01:09.282Z
Reserved: 2026-09-29T17:33:19.820Z
Link: CVE-2026-102879
No data.
Status : Received
Published: 2026-09-29T20:17:18.797
Modified: 2026-09-29T20:17:18.797
Link: CVE-2026-102879
No data.
OpenCVE Enrichment
No data.