<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>PullMD (3.2.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/pullmd-3.2.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 20 Aug 2026 03:09:27 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/pullmd-3.2.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>SSRF Vulnerability in AeternaLabsHQ PullMD</title><link>https://feed.craftedsignal.io/briefs/2026-08-pullmd-ssrf/</link><pubDate>Thu, 20 Aug 2026 03:09:27 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-pullmd-ssrf/</guid><description>AeternaLabsHQ PullMD version 3.2.0 contains a Server-Side Request Forgery vulnerability in the REST API endpoint that allows remote attackers to perform unauthorized outbound requests.</description><content:encoded><![CDATA[<p>AeternaLabsHQ PullMD version 3.2.0 is affected by a Server-Side Request Forgery (SSRF) vulnerability. The vulnerability resides within the REST API component, specifically involving the /api endpoint. An attacker can exploit this by manipulating the 'url' argument, which the application fails to adequately sanitize or validate. This flaw allows remote, unauthenticated actors to force the server to make arbitrary HTTP requests to internal or external resources, potentially leading to unauthorized data access, network scanning, or interaction with internal services that are not directly exposed to the internet. The vulnerability has been addressed in version 3.3.0, and users are strongly advised to upgrade to this version to mitigate the risk associated with CVE-2026-76795.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability carries a CVSS v3.1 base score of 7.3, indicating a significant risk. If exploited, an attacker could abuse the PullMD server as a proxy to reach internal network segments, bypass firewall controls, or access metadata services (like IMDS in cloud environments) to steal credentials or sensitive application data.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade AeternaLabsHQ PullMD to version 3.3.0 immediately as specified in the vendor security advisory.</li>
<li>Implement egress filtering at the network level for the server hosting PullMD to restrict outbound connections to only necessary and known-good external domains or IP addresses.</li>
<li>Deploy the Sigma rule below to monitor for suspicious requests to the /api endpoint containing anomalous 'url' parameters.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>