CVE-2026-5205: chatwoot Webhook API trigger.rb Trigger server-side request forgery
A vulnerability was identified in chatwoot up to 4.11.2. Affected by this vulnerability is the function Webhooks::Trigger in the library lib/webhooks/trigger.rb of the component Webhook API. Such manipulation of the argument url leads to server-side request forgery. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5205?
CVE-2026-5205 has been classified as a medium severity vulnerability due to its potential for server-side request forgery.
How do I fix CVE-2026-5205?
To fix CVE-2026-5205, update Chatwoot to version 4.11.3 or later, which addresses the vulnerability.
What software is affected by CVE-2026-5205?
CVE-2026-5205 affects Chatwoot versions up to and including 4.11.2.
What is server-side request forgery in the context of CVE-2026-5205?
In the context of CVE-2026-5205, server-side request forgery allows an attacker to manipulate the argument URL in webhook triggers, potentially leading to unauthorized requests.
Is there a workaround for CVE-2026-5205?
There are no official workarounds for CVE-2026-5205; upgrading to the patched version is the recommended approach.