SSRF Vulnerability in feelcrm-os via GoogleController
An unauthenticated server-side request forgery (SSRF) vulnerability in feelcrm-os 1.0.0 allows remote attackers to force the server to perform unauthorized HTTP requests by manipulating the url parameter.
CVE search metadata
CVE search record: CVE-2026-105290. Severity: high. CVSS: 7.3. KEV: no. Product: feelcrm-os (1.0.0). Brief: SSRF Vulnerability in feelcrm-os via GoogleController. Brief link: https://feed.craftedsignal.io/briefs/2026-10-feelcrm-ssrf/
CVE-2026-105290 identifies a critical server-side request forgery (SSRF) vulnerability within feelcrm-os version 1.0.0. The vulnerability resides in the getCurlData endpoint, specifically within the file App/Feelcrm/Index/Controller/GoogleController.class.php. An attacker can supply a malicious URL through the 'url' argument, which the application then requests on behalf of the server. This allows remote, unauthenticated attackers to interact with internal network resources or external services, potentially leading to unauthorized data exfiltration or access to internal administration interfaces. Public disclosure of the vulnerability has occurred, and as of the publication date, the project maintainers have not released a patch or responded to initial vulnerability reports.
Impact
Successful exploitation of this vulnerability allows an attacker to bypass perimeter security to scan and interact with internal network services that are otherwise inaccessible from the public internet. This can lead to unauthorized access to cloud metadata services, internal API endpoints, or private management interfaces, potentially resulting in complete compromise of the underlying server if secondary vulnerabilities are identified within the internal network.
Recommendation
- Restrict outbound network access from the host running feelcrm-os to only essential external services, effectively neutralizing the impact of potential SSRF exploitation.
- Implement strict input validation on the 'url' parameter for the GoogleController endpoint to permit only expected domain patterns.
- Monitor web access logs for anomalous requests to the '/App/Feelcrm/Index/Controller/GoogleController.class.php' path, particularly those containing suspicious URL parameters or attempts to access internal IP addresses (e.g., 127.0.0.1, 169.254.169.254).
- Monitor for potential exploitation attempts targeting this specific file until an official vendor patch is released.
Immediate actions
Deploy webserver detection rule to monitor for internal IP requests
Threat Hunt
Logs showing hits to GoogleController.class.php with URL parameters containing internal IP addresses
Data: Web server access logs
Mitigations
Restrict outbound egress from the web server hosting feelcrm-os
CVE-2026-105290
Detection coverage 1
Detect CVE-2026-105290 Exploitation - SSRF in feelcrm-os
highDetects exploitation of CVE-2026-105290 by identifying suspicious URL arguments in requests to the GoogleController endpoint that target private address spaces.
Detection queries are available on the platform. Get full rules →