CVE-2026-33619 describes a Server-Side Request Forgery (SSRF) vulnerability in PinchTab v0.8.3's optional scheduler webhook delivery path. This flaw allows an attacker to specify a malicious callback URL, causing the PinchTab server to make blind HTTP POST requests to arbitrary internal or external destinations when a task completes. Rated Medium (CVSS 4.1), exploitation typically requires high privileges (e.g., the master API token) and the scheduler to be enabled, potentially leading to limited integrity impact by interacting with other services. There is currently no evidence of active exploitation, nor is any public exploit code or significant community discussion available for this vulnerability. The issue was addressed in PinchTab v0.8.4 by implementing robust validation of callback targets and disabling redirect following.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.8.4CPE matchmatch criteria | cpe:2.3:a:pinchtab:pinchtab:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.