{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/noncegeek/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:noncegeek:dim-sum-app:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-94038"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["dim-sum-app"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["NonceGeek"],"content_html":"\u003cp\u003eCVE-2026-94038 describes a critical server-side request forgery (SSRF) vulnerability identified in the NonceGeek dim-sum-app. The flaw specifically resides in the \u003ccode\u003etextSearchV2Handler\u003c/code\u003e function located within \u003ccode\u003edeno/main.tsx\u003c/code\u003e of the Deno backend component. By supplying a malicious value to the \u003ccode\u003esupabase_url\u003c/code\u003e argument, a remote, unauthenticated attacker can force the application to perform unauthorized HTTP requests to arbitrary internal or external targets. This exposure can be leveraged to interact with internal infrastructure, query local services, or perform reconnaissance within the target network environment. The vulnerability has been publicly disclosed, and a patch (commit \u003ccode\u003e8389032e5d52c28c4855c6126ca7d0eae8af346a\u003c/code\u003e) is available to remediate this issue.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows remote actors to bypass network perimeter controls and perform SSRF, potentially leading to unauthorized data exfiltration or access to internal resources normally unreachable from the public internet.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the immediate application of the security patch provided by the vendor. Organizations should audit their web server and proxy logs for unusual outbound requests originating from the server hosting the Deno backend, specifically monitoring for anomalous calls targeting internal IP ranges or sensitive internal metadata endpoints.\u003c/p\u003e\n","date_modified":"2026-09-20T18:22:47Z","date_published":"2026-09-20T18:22:47Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-94038/","summary":"A server-side request forgery vulnerability (CVE-2026-94038) in the NonceGeek dim-sum-app Deno backend allows remote attackers to manipulate the supabase_url parameter for unauthorized server-side requests.","title":"SSRF Vulnerability in NonceGeek dim-sum-app","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-94038/"}],"language":"en","title":"CraftedSignal Threat Feed - NonceGeek","version":"https://jsonfeed.org/version/1.1"}