CVE-2026-3789 is a high-severity Server-Side Request Forgery (SSRF) vulnerability affecting Bytedesk versions up to 1.3.9, specifically within the SpringAIGiteeRestController component. This flaw, rated 8.8 CVSS, allows a remote attacker with low privileges and low attack complexity to manipulate the apiUrl argument, leading to high impacts on confidentiality, integrity, and availability. The vulnerability is remotely exploitable without user interaction. While an exploit is publicly available, it is not yet integrated into common exploit frameworks like Metasploit or Nuclei. There is currently no significant community discussion or media coverage regarding this CVE, but organizations are advised to upgrade to Bytedesk version 1.4.5.4 to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.4.5.4CPE matchmatch criteria | cpe:2.3:a:bytedesk:bytedesk:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.