CVE-2026-28677 describes a Server-Side Request Forgery (SSRF) vulnerability in OpenSift, an AI study tool, affecting versions prior to 1.6.3-alpha. The flaw allowed attackers to manipulate the URL ingest pipeline with user-controlled remote URLs, bypassing existing private/local host checks due to missing restrictions on credentialed URLs, non-standard ports, and cross-host redirects. This vulnerability is rated as High severity (CVSS 8.2), indicating it can be exploited remotely with low complexity and no user interaction, potentially leading to high confidentiality impact (e.g., data exfiltration) and low availability impact. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is currently available. Community discussion is minimal, with only one mention identified.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.6.3CPE matchmatch criteria | cpe:2.3:a:opensift:opensift:*:*:*:*:*:python:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.