CVE-2026-87821: Lara Dashboard 0.9.2 through 1.3.1 Server-Side Request Forgery in Builder Markdown Fetch

Published Sep 9, 2026
·
Updated

Lara Dashboard through 1.3.1 contains a server-side request forgery vulnerability in the POST /api/admin/builder/markdown/fetch endpoint that allows any authenticated user to fetch arbitrary URLs and read the response body. Attackers can read internal HTTP services and cloud metadata including IAM credentials by supplying malicious URLs without host validation or redirect restrictions.

Affected Software

1 affected component
Lara Dashboard Lara Dashboard>0.9.2<=1.3.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Lara Dashboard to a version that resolves this vulnerability.

    Fixed in 1.3.1
  2. Configuration

    Modify the POST /api/admin/builder/markdown/fetch behavior to validate the supplied URL host against an allowlist and prevent redirects to internal services or metadata endpoints.

    Lara Dashboard /api/admin/builder/markdown/fetch host validation and redirect restrictions = enable strict host validation and disallow redirects to untrusted/internal destinations
  3. Compensating control

    Restrict network access from the application so the server running Lara Dashboard cannot reach internal HTTP services or cloud metadata endpoints (including IAM credential metadata).

Event History

Sep 9, 2026
CVE Published
via MITRE·11:21 AM
Data Sourced
via MITRE·11:21 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

Any authenticated Lara Dashboard user can exploit it. No user interaction is required, and the vulnerable endpoint is reachable over the network.

2

What can an attacker access through the vulnerable endpoint?

An attacker can cause the server to fetch arbitrary URLs and read the response body. This can expose internal HTTP services and cloud metadata, including IAM credentials.

3

What URL protections are missing?

The endpoint does not enforce host validation or redirect restrictions. A supplied URL can therefore target internal resources or redirect to them.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203