{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-87821","assignerOrgId":"83251b91-4cc7-4094-a5c7-464a1b83ea10","state":"PUBLISHED","assignerShortName":"VulnCheck","dateReserved":"2026-09-09T10:32:34.110Z","datePublished":"2026-09-09T11:21:06.740Z","dateUpdated":"2026-09-09T12:08:03.123Z"},"containers":{"cna":{"providerMetadata":{"orgId":"83251b91-4cc7-4094-a5c7-464a1b83ea10","shortName":"VulnCheck","dateUpdated":"2026-09-09T11:21:06.740Z"},"datePublic":"2026-09-05T00:00:00.000Z","title":"Lara Dashboard 0.9.2 through 1.3.1 Server-Side Request Forgery in Builder Markdown Fetch","descriptions":[{"lang":"en","value":"Lara Dashboard through 1.3.1 contains a server-side request forgery vulnerability in the POST /api/admin/builder/markdown/fetch endpoint that allows any authenticated user to fetch arbitrary URLs and read the response body. Attackers can read internal HTTP services and cloud metadata including IAM credentials by supplying malicious URLs without host validation or redirect restrictions."}],"problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-918","description":"Server-Side Request Forgery (SSRF)","type":"CWE"}]}],"affected":[{"vendor":"laradashboard","product":"laradashboard","collectionURL":"https://github.com/laradashboard/laradashboard","repo":"https://github.com/laradashboard/laradashboard","defaultStatus":"unaffected","packageURL":"pkg:github/laradashboard/laradashboard","versions":[{"version":"0.9.2","lessThan":"1.3.2","status":"affected","versionType":"semver"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*","versionStartIncluding":"0.9.2","versionEndExcluding":"1.3.2"}]}]}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":7.1,"baseSeverity":"HIGH"}},{"format":"CVSS","cvssV4_0":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","baseScore":7.1,"baseSeverity":"HIGH"}}],"references":[{"url":"https://github.com/laradashboard/laradashboard/security/advisories/GHSA-4xqv-4c27-6c4j","tags":["vendor-advisory"],"name":"GitHub Security Advisory (GHSA-4xqv-4c27-6c4j)"},{"url":"https://github.com/laradashboard/laradashboard/security/advisories/GHSA-f36j-h77g-6wj8","tags":["vendor-advisory"],"name":"GitHub Security Advisory (GHSA-f36j-h77g-6wj8)"},{"url":"https://github.com/laradashboard/laradashboard/commit/738cc1a219ce459323ef1d09c3789075f1b8d2f2","tags":["patch"],"name":"Fix commit adding SafeUrlValidator"},{"url":"https://github.com/laradashboard/laradashboard/blob/v1.3.1/app/Services/Builder/MarkdownFetchService.php","tags":["technical-description"],"name":"Unguarded server-side fetch at v1.3.1"},{"url":"https://github.com/laradashboard/laradashboard/blob/v0.9.2/app/Services/Builder/MarkdownFetchService.php","tags":["technical-description"],"name":"Same unguarded fetch at v0.9.2, the first release carrying the service"},{"url":"https://github.com/laradashboard/laradashboard/blob/v1.3.1/app/Http/Controllers/Api/Builder/MarkdownController.php","tags":["technical-description"],"name":"Controller with no authorization check at v1.3.1"},{"url":"https://github.com/laradashboard/laradashboard/blob/v1.3.2/app/Support/Security/SafeUrlValidator.php","tags":["technical-description"],"name":"Host allowlist introduced in v1.3.2"},{"url":"https://github.com/laradashboard/laradashboard/releases/tag/v1.3.2","tags":["release-notes"],"name":"laradashboard v1.3.2 Release Notes"},{"url":"https://github.com/laradashboard/laradashboard","tags":["product"]},{"name":"VulnCheck Advisory: Lara Dashboard 0.9.2 through 1.3.1 Server-Side Request Forgery in Builder Markdown Fetch","tags":["third-party-advisory"],"url":"https://www.vulncheck.com/advisories/lara-dashboard-0.9.2-through-1.3.1-server-side-request-forgery-in-builder-markdown-fetch"}],"credits":[{"lang":"en","value":"EVIL0RD","type":"finder"}],"x_generator":{"engine":"vulncheck-endgame"},"source":{"discovery":"EXTERNAL"}},"adp":[{"references":[{"url":"https://github.com/laradashboard/laradashboard/security/advisories/GHSA-4xqv-4c27-6c4j","tags":["exploit"]}],"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-09-09T12:05:47.404761Z","id":"CVE-2026-87821","options":[{"Exploitation":"poc"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-09T12:08:03.123Z"}}]}}