{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/librarian-3.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.1,"id":"CVE-2024-54819"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Librarian (3.1)"],"_cs_severities":["high"],"_cs_tags":["ssrf","web-vulnerability","librarian","cve-2024-54819"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eCVE-2024-54819 is a high-severity vulnerability (CVSS 9.1) affecting the Librarian application, specifically within the PDF generation module. The flaw exists due to insufficient validation of the 'remote_url' parameter when the application processes PDF save requests. An attacker with valid credentials can manipulate this parameter to force the server to initiate arbitrary HTTP requests to internal network segments, effectively acting as an SSRF vector.\u003c/p\u003e\n\u003cp\u003eThis vulnerability was disclosed with proof-of-concept exploit code demonstrating how to leverage the 'remote_url' field in conjunction with valid authentication cookies and a CSRF token. By bypassing input validation, attackers can probe internal services or interact with locally hosted applications that are otherwise inaccessible from the public internet. Organizations using Librarian should audit their access logs for unusual POST requests to the PDF save endpoint, particularly those containing non-standard or internal URLs in the 'remote_url' field.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs credential harvesting or utilizes valid account access to gain an authenticated session for the Librarian application.\u003c/li\u003e\n\u003cli\u003eAttacker obtains a valid session cookie (e.g., IL=[COOKIE]) and current CSRF token from the application's authenticated session.\u003c/li\u003e\n\u003cli\u003eAttacker targets the \u003ccode\u003e/librarian/index.php/pdf/save\u003c/code\u003e endpoint to initiate a PDF generation request.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious HTTP POST request, supplying an internal IP address or internal hostname within the 'remote_url' parameter.\u003c/li\u003e\n\u003cli\u003eThe Librarian server receives the POST request and fails to sanitize the 'remote_url' input.\u003c/li\u003e\n\u003cli\u003eThe server-side service initiates an outbound request to the target URI specified by the attacker, effectively performing SSRF.\u003c/li\u003e\n\u003cli\u003eAttacker receives information or state changes from the internal resource, facilitating further lateral movement or data exfiltration.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this SSRF vulnerability grants an authenticated attacker the ability to bypass network segmentation and interact with internal-only services or APIs. This could lead to the exposure of sensitive internal data, exploitation of secondary internal vulnerabilities, or administrative access to other internal systems.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eMonitor web server logs for HTTP POST requests to \u003ccode\u003e/librarian/index.php/pdf/save\u003c/code\u003e that exhibit suspicious 'remote_url' parameters, such as internal IP addresses (e.g., 127.0.0.1, 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16).\u003c/li\u003e\n\u003cli\u003eDeploy the provided Sigma rule to detect attempts at exploiting the endpoint.\u003c/li\u003e\n\u003cli\u003eImplement strict allow-listing for the 'remote_url' parameter on the server side to ensure only trusted, external domains are reachable.\u003c/li\u003e\n\u003cli\u003eEnsure that the web server running Librarian is appropriately firewalled to minimize the impact of SSRF if this vulnerability is present.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-05T01:15:33Z","date_published":"2026-09-05T01:15:33Z","id":"https://feed.craftedsignal.io/briefs/2026-09-librarian-ssrf/","summary":"An authenticated Server-Side Request Forgery (SSRF) vulnerability in the Librarian PDF save endpoint allows attackers to perform unauthorized requests against internal network resources.","title":"Librarian PDF Save Endpoint SSRF Vulnerability (CVE-2024-54819)","url":"https://feed.craftedsignal.io/briefs/2026-09-librarian-ssrf/"}],"language":"en","title":"CraftedSignal Threat Feed - Librarian (3.1)","version":"https://jsonfeed.org/version/1.1"}