CVE-2026-102879: ClaraVerse through 0.3.1 SSRF Protection Bypass
ClaraVerse through 0.3.1 contains server-side request forgery protection bypasses in the downloadfile and scrapeweb agent tools. Authenticated users can bypass hostname validation and IPv6 transition address filtering to make the server request internal services and cloud instance metadata endpoints.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated ClaraVerse user can exploit the affected download_file and scrape_web agent tools. The attack can be performed remotely and does not require user interaction.
What resources could be reached through the bypass?
An attacker can cause the ClaraVerse server to request internal services and cloud instance metadata endpoints by bypassing hostname validation and IPv6 transition address filtering.
Are deployments affected by default?
The available information identifies ClaraVerse through version 0.3.1 as affected, but it does not state whether the vulnerable agent tools are enabled or reachable in a default deployment.