<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>TDuck (&lt;= 5.3) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/tduck--5.3/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 16 Sep 2026 19:51:40 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/tduck--5.3/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Unauthenticated Form Submission Exfiltration in TDuck</title><link>https://feed.craftedsignal.io/briefs/2026-09-tduck-webhook-vuln/</link><pubDate>Wed, 16 Sep 2026 19:51:40 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-tduck-webhook-vuln/</guid><description>TDuck survey form through version 5.3 contains a vulnerability allowing authenticated attackers to attach unauthorized webhooks to arbitrary forms for data exfiltration.</description><content:encoded><![CDATA[<p>TDuck survey form versions 5.3 and earlier contain a critical vulnerability in the WebhookConfigController. The application fails to properly validate webhook destination URLs and lacks sufficient authorization checks to verify form ownership. This flaw allows an authenticated attacker to associate arbitrary webhook endpoints with any form within the instance. By doing so, the attacker can intercept and exfiltrate sensitive submission data as it is processed by the application. This vulnerability is significant as it facilitates the silent theft of user-provided data, potentially leading to unauthorized access to PII or internal organizational information. Impacted organizations using TDuck for data collection must identify and update instances to a patched version to prevent data exfiltration.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows authenticated attackers to exfiltrate all incoming form submissions to external or internal attacker-controlled endpoints. This impacts any organization relying on TDuck for private survey data collection, resulting in a complete breach of confidentiality for submitted form data.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Update TDuck to the latest patched version immediately. Monitor server-side web application logs for unusual POST requests directed toward the WebhookConfigController, specifically tracking associations of new or unknown external webhook URLs to existing forms.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>