CVE-2026-92527: chatwoot Shopify OAuth callbacks_controller.rb server-side request forgery
A vulnerability has been found in chatwoot up to 4.17.1. This impacts an unknown function of the file callbackscontroller.rb of the component Shopify OAuth. The manipulation leads to server-side request forgery. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
Which deployments are potentially affected?
Chatwoot versions up to 4.17.1 are identified as affected. The issue is in the Shopify OAuth component's callbacks_controller.rb file.
What level of access does an attacker need?
The supplied severity vector indicates network-reachable exploitation with low privileges required and no user interaction. The vulnerability is described as remotely exploitable.
Is there evidence that exploitation may occur in practice?
An exploit has been publicly disclosed and may be used. The provided data does not state whether active exploitation has been observed.
Is a vendor fix available?
The provided information does not identify a fix or patched release. It states that the project was notified through an issue report but had not responded.