{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/tduck--5.3/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:tduck:tduck:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.1,"id":"CVE-2026-92602"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["TDuck (\u003c= 5.3)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["TDuck"],"content_html":"\u003cp\u003eTDuck survey form versions 5.3 and earlier contain a critical vulnerability in the WebhookConfigController. The application fails to properly validate webhook destination URLs and lacks sufficient authorization checks to verify form ownership. This flaw allows an authenticated attacker to associate arbitrary webhook endpoints with any form within the instance. By doing so, the attacker can intercept and exfiltrate sensitive submission data as it is processed by the application. This vulnerability is significant as it facilitates the silent theft of user-provided data, potentially leading to unauthorized access to PII or internal organizational information. Impacted organizations using TDuck for data collection must identify and update instances to a patched version to prevent data exfiltration.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows authenticated attackers to exfiltrate all incoming form submissions to external or internal attacker-controlled endpoints. This impacts any organization relying on TDuck for private survey data collection, resulting in a complete breach of confidentiality for submitted form data.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eUpdate TDuck to the latest patched version immediately. Monitor server-side web application logs for unusual POST requests directed toward the WebhookConfigController, specifically tracking associations of new or unknown external webhook URLs to existing forms.\u003c/p\u003e\n","date_modified":"2026-09-16T19:51:40Z","date_published":"2026-09-16T19:51:40Z","id":"https://feed.craftedsignal.io/briefs/2026-09-tduck-webhook-vuln/","summary":"TDuck survey form through version 5.3 contains a vulnerability allowing authenticated attackers to attach unauthorized webhooks to arbitrary forms for data exfiltration.","title":"Unauthenticated Form Submission Exfiltration in TDuck","url":"https://feed.craftedsignal.io/briefs/2026-09-tduck-webhook-vuln/"}],"language":"en","title":"CraftedSignal Threat Feed - TDuck (\u003c= 5.3)","version":"https://jsonfeed.org/version/1.1"}