Vendor
Hi.Events fails to re-validate webhook destinations at dispatch time, allowing attackers to perform Server-Side Request Forgery (SSRF) and exfiltrate internal data via redirects.