PatchSiren cyber security CVE debrief
CVE-2026-108523 Studio-Saelix CVE debrief
A server-side request forgery vulnerability was determined in Studio-Saelix Sencho up to 0.94.1, affecting the git-sources Browse API Endpoint in the outboundTarget.ts file. This issue allows remote attackers to manipulate the repo_url argument, potentially leading to unauthorized requests. The exploit has been publicly disclosed, but the presence of this vulnerability remains uncertain. A patch (79b86ddcd4aefdd6941f098e35990ab397b13c72) has been applied to correct this issue. The vendor disputes the CVE characterization, stating that git repository access is an intentional, privileged administrative function and that the report does not demonstrate a privilege-boundary bypass or access by an unprivileged user.
- Vendor
- Studio-Saelix
- Product
- Sencho
- CVSS
- LOW 2.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-11
- Original CVE updated
- 2026-10-11
- Advisory published
- 2026-10-11
- Advisory updated
- 2026-10-11
Who should care
Sencho administrators, security teams, and developers responsible for maintaining and securing Studio-Saelix Sencho deployments should assess exposure and verify the presence and impact of this vulnerability.
Why it matters
This server-side request forgery vulnerability in Studio-Saelix Sencho's git-sources Browse API Endpoint requires attention from Sencho administrators and security teams to assess exposure, verify the presence and impact of the vulnerability, and apply the patch to prevent potential exploitation.
- Potential unauthorized requests to internal or external resources
- Possible data breaches or system compromise
- Need for verification of vulnerability presence and impact
- Priority for applying the patch to prevent potential exploitation
Technical summary
The vulnerability affects the git-sources Browse API Endpoint in the outboundTarget.ts file of Studio-Saelix Sencho up to 0.94.1. A manipulation of the repo_url argument can lead to server-side request forgery, allowing remote attackers to perform unauthorized requests. The exploit has been publicly disclosed, and a patch has been applied to correct this issue. The vulnerability requires attention from Sencho administrators and security teams to assess exposure, verify the presence and impact of the vulnerability, and apply the patch to prevent potential exploitation. The vendor disputes the CVE characterization, stating that git repository access is an intentional, privileged administrative function and that
Defensive priority
Medium priority for Sencho administrators and security teams
Recommended defensive actions
- Review and apply the patch (79b86ddcd4aefdd6941f098e35990ab397b13c72) to correct the issue
- Verify the presence and impact of this vulnerability in your Sencho deployment
- Monitor Sencho logs for suspicious requests to the git-sources Browse API Endpoint
- Perform a thorough review of the git-sources Browse API Endpoint configuration
- Implement additional monitoring and logging to detect potential exploitation attempts
- Conduct a security audit to identify potential vulnerabilities in other components
- Review and update incident response plans to address potential exploitation of this vulnerability
Evidence notes
The CVE record and source item provide details about the vulnerability, its potential impact, and the patch applied. However, the presence of the vulnerability remains uncertain, and the vendor disputes the CVE characterization.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-108523 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-108523
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-108523 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108523
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Studio-Saelix Sencho git-sources Browse API Endpoint outboundTarget.ts server-side request forge
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/108xxx/CVE-2026-108523.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/416189
Supplemental source - vdb-entry, technical-description
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/416189/cti
Supplemental source - signature, permissions-required
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/cve/CVE-2026-108523
Supplemental source - third-party-advisory
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/submit/893367
Supplemental source - third-party-advisory
-
Source reference
Unverified legacy reference
URL: https://gist.github.com/jovair1994/93446c14d30a16313e830490d71bbd1d
Supplemental source - exploit
-
Source reference
Unverified legacy reference
URL: https://github.com/Studio-Saelix/sencho/pull/1877
Supplemental source - issue-tracking, patch
-
Source reference
Unverified legacy reference
URL: https://github.com/Studio-Saelix/sencho/commit/79b86ddcd4aefdd6941f098e35990ab397b13c72
Supplemental source - patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.