gist.github.com Critical Vulnerabilities in SurfSense Expose Users to Remote Attacks
Article Content
- •SurfSense version 0.0.36 has critical vulnerabilities allowing remote exploitation.
- •Unauthenticated access to webhooks can lead to unauthorized document creation and overwriting.
- •Authenticated users can execute arbitrary commands as root, risking the entire backend environment.
Two critical vulnerabilities have been identified in MODSetter's SurfSense version 0.0.36, affecting its FastAPI backend. The first vulnerability allows unauthenticated users to exploit the POST /api/v1/webhooks/circleback/{workspace_id} endpoint, enabling them to create or overwrite documents in any workspace. This flaw is classified as Missing Authentication / Broken Access Control (CWE-306, CWE-862) with a CVSS score of 8.7. The second vulnerability involves OS Command Injection through the POST /api/v1/connectors/mcp/test endpoint, allowing authenticated users to execute arbitrary commands as root, with a CVSS score of 9.4. Both vulnerabilities pose significant risks in multi-tenant environments, potentially exposing sensitive data across tenants. The vulnerabilities were disclosed on September 29, 2026, and immediate action is recommended to mitigate risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
CISA Adds Seven Exploited Vulnerabilities; IBM Warns of Langflow OSS Flaws CISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities Catalog, including CVE-2026-9586, a SQL injection vulnerability in Sangoma Switchvox, and several others affecting SonicWall and JFrog products. These vulnerabilities pose significant risks due to active exploitation. Concurrently, IBM has…