Skip to content
Critical Vulnerabilities in SurfSense Expose Users to Remote Attacks

Critical Vulnerabilities in SurfSense Expose Users to Remote Attacks

First seen 29 Sep 2026, 11:08 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 29, 2026 at 11:09 UTC
  • •SurfSense version 0.0.36 has critical vulnerabilities allowing remote exploitation.
  • •Unauthenticated access to webhooks can lead to unauthorized document creation and overwriting.
  • •Authenticated users can execute arbitrary commands as root, risking the entire backend environment.

Two critical vulnerabilities have been identified in MODSetter's SurfSense version 0.0.36, affecting its FastAPI backend. The first vulnerability allows unauthenticated users to exploit the POST /api/v1/webhooks/circleback/{workspace_id} endpoint, enabling them to create or overwrite documents in any workspace. This flaw is classified as Missing Authentication / Broken Access Control (CWE-306, CWE-862) with a CVSS score of 8.7. The second vulnerability involves OS Command Injection through the POST /api/v1/connectors/mcp/test endpoint, allowing authenticated users to execute arbitrary commands as root, with a CVSS score of 9.4. Both vulnerabilities pose significant risks in multi-tenant environments, potentially exposing sensitive data across tenants. The vulnerabilities were disclosed on September 29, 2026, and immediate action is recommended to mitigate risks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-29
Critical vulnerabilities disclosed
MODSetter disclosed two critical vulnerabilities in SurfSense 0.0.36, affecting its FastAPI backend.
gist.github.com
2026-09-29
Vulnerability details published
Details of the vulnerabilities, including CVSS scores and attack vectors, were published on GitHub.
gist.github.com

More articles in this cluster (2)