Back is.yuum.me 2026 08 06 Ssrf Vulnerability In Vocechat Server V0520
In the file src/api/resource.rs , the open_graphic_parse function directly passes the user-supplied url parameter to open_graph::fetch() without any protocol validation, IP address filtering, or authentication checks.
This can be exploited by sending a crafted GET request to /api/resource/open_graphic_parse with a malicious URL, forcing the server to initiate HTTP requests to arbitrary internal or external targets.
The endpoint is fully unauthenticated; any user with network access to the VoceChat service can exploit this vulnerability without registering or logging in.
Example SSRF Payloads:
The following payloads can be used to probe internal services or access cloud metadata: plain http:// :3000/api/resource/open_graphic_parse?url= http:// :3000/api/resource/open_graphic_parse?url= http:// :3000/api/resource/open_graphic_parse?url=
The following payloads can be used to probe internal services or access cloud metadata:
Requesting the Vulnerable Endpoint:
Make an unauthenticated GET request to the vulnerable endpoint: plain GET /api/resource/open_graphic_parse?url= HTTP/1.1 Host: target:3000 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 Connection: close
Make an unauthenticated GET request to the vulnerable endpoint:
Verifying the Exploit:
If the exploit is successful, the server will return Open Graph metadata, service banners, or error messages from the targeted internal resource, confirming that unauthorized SSRF is possible.
In cloud environments (AWS/Alibaba Cloud/Tencent Cloud), successful access to 169.254.169.254 may leak IAM role temporary credentials, leading to full cloud account compromise.
Deploy the vulnerable application:
Access the vulnerable endpoint without authentication:
Observe the response:
The server will return JSON data containing Open Graph metadata or raw response content from the internal target, confirming that the server performed an unauthorized outbound request on behalf of the attacker.
Impact: Internal network reconnaissance, service information disclosure, lateral movement, and cloud metadata credential theft.
Root Cause: The url parameter is fully user-controlled with no whitelist validation, no internal IP blocking, no protocol restrictions, and no authentication requirement.
Remediation: Add authentication to the endpoint, implement URL whitelist validation, block private IP ranges ( 127.0.0.0/8 , 10.0.0.0/8 , 172.16.0.0/12 , 192.168.0.0/16 , 169.254.0.0/16 ), and apply DNS rebinding protection.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
