{"id":"CVE-2026-88403","published":"2026-09-21T21:17:14.390","lastModified":"2026-09-22T20:00:03.713","description":"A Server-Side Request Forgery (SSRF) in the serverRequest function of nocobase v2.1.21 allows authenticated attackers to scan internal resources via a crafted HTTP request.","cvssScore":6.5,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","cwes":["CWE-918"],"vendors":[],"products":[],"references":[{"url":"https://github.com/czx1111/cve/issues/7","tags":[]},{"url":"https://github.com/czx1111/cve/issues/7","tags":[]}],"exploitRefs":[{"url":"https://github.com/czx1111/cve/issues/7","tags":[]},{"url":"https://github.com/czx1111/cve/issues/7","tags":[]}],"hasPoc":true,"ai":null}