{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/jina-ai/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-18647"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Reader"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"threat","_cs_vendors":["Jina AI"],"content_html":"\u003cp\u003eA server-side request forgery (SSRF) vulnerability (CVE-2026-18647) has been identified in the Jina AI Reader component, specifically within the 'isValidTLD' function located in '/backend/functions/src/cloud-functions/crawler.ts'. The flaw exists in the Crawler/Puppeteer module and allows a remote attacker to manipulate the crawler's input, resulting in the ability to force the server to make arbitrary requests to internal or external resources. The vulnerability affects all versions of Jina AI Reader up to commit 1574bfd380d249c86c82db4dace0d9c8fe17e2b1. Because Jina AI Reader utilizes a rolling release model, users are encouraged to update their deployment to the latest available build to mitigate the risk. Public exploit code for this vulnerability has been disclosed, increasing the likelihood of opportunistic exploitation in the wild.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-18647 allows an attacker to bypass network perimeter controls by leveraging the server as a proxy. This can lead to the exfiltration of internal service metadata, unauthorized interaction with internal APIs, or port scanning of internal network segments that are not otherwise accessible from the internet. The vulnerability poses a high risk to organizations hosting Jina AI Reader in cloud environments where the service may have elevated network privileges.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate Jina AI Reader to the latest version to include the patch for the 'isValidTLD' function.\u003c/li\u003e\n\u003cli\u003eReview cloud environment egress policies for the server hosting the Jina AI Reader component to restrict connectivity to internal-only endpoints (e.g., 169.254.169.254, internal RFC1918 subnets).\u003c/li\u003e\n\u003cli\u003eInspect web server access logs for anomalous requests directed at the crawler endpoint that contain unexpected or internal IP addresses in query parameters.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-03T22:48:59Z","date_published":"2026-08-03T22:48:59Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-18647/","summary":"An unauthenticated server-side request forgery (SSRF) vulnerability in the Jina AI Reader crawler allows remote attackers to perform unauthorized requests, with public exploit code currently available.","title":"SSRF Vulnerability in Jina AI Reader Crawler","url":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-18647/"}],"language":"en","title":"CraftedSignal Threat Feed - Jina AI","version":"https://jsonfeed.org/version/1.1"}