PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-108523 Studio-Saelix CVE debrief

A server-side request forgery vulnerability was determined in Studio-Saelix Sencho up to 0.94.1, affecting the git-sources Browse API Endpoint in the outboundTarget.ts file. This issue allows remote attackers to manipulate the repo_url argument, potentially leading to unauthorized requests. The exploit has been publicly disclosed, but the presence of this vulnerability remains uncertain. A patch (79b86ddcd4aefdd6941f098e35990ab397b13c72) has been applied to correct this issue. The vendor disputes the CVE characterization, stating that git repository access is an intentional, privileged administrative function and that the report does not demonstrate a privilege-boundary bypass or access by an unprivileged user.

Vendor
Studio-Saelix
Product
Sencho
CVSS
LOW 2.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-11
Original CVE updated
2026-10-11
Advisory published
2026-10-11
Advisory updated
2026-10-11

Who should care

Sencho administrators, security teams, and developers responsible for maintaining and securing Studio-Saelix Sencho deployments should assess exposure and verify the presence and impact of this vulnerability.

Why it matters

This server-side request forgery vulnerability in Studio-Saelix Sencho's git-sources Browse API Endpoint requires attention from Sencho administrators and security teams to assess exposure, verify the presence and impact of the vulnerability, and apply the patch to prevent potential exploitation.

  • Potential unauthorized requests to internal or external resources
  • Possible data breaches or system compromise
  • Need for verification of vulnerability presence and impact
  • Priority for applying the patch to prevent potential exploitation

Technical summary

The vulnerability affects the git-sources Browse API Endpoint in the outboundTarget.ts file of Studio-Saelix Sencho up to 0.94.1. A manipulation of the repo_url argument can lead to server-side request forgery, allowing remote attackers to perform unauthorized requests. The exploit has been publicly disclosed, and a patch has been applied to correct this issue. The vulnerability requires attention from Sencho administrators and security teams to assess exposure, verify the presence and impact of the vulnerability, and apply the patch to prevent potential exploitation. The vendor disputes the CVE characterization, stating that git repository access is an intentional, privileged administrative function and that

Defensive priority

Medium priority for Sencho administrators and security teams

Recommended defensive actions

  • Review and apply the patch (79b86ddcd4aefdd6941f098e35990ab397b13c72) to correct the issue
  • Verify the presence and impact of this vulnerability in your Sencho deployment
  • Monitor Sencho logs for suspicious requests to the git-sources Browse API Endpoint
  • Perform a thorough review of the git-sources Browse API Endpoint configuration
  • Implement additional monitoring and logging to detect potential exploitation attempts
  • Conduct a security audit to identify potential vulnerabilities in other components
  • Review and update incident response plans to address potential exploitation of this vulnerability

Evidence notes

The CVE record and source item provide details about the vulnerability, its potential impact, and the patch applied. However, the presence of the vulnerability remains uncertain, and the vendor disputes the CVE characterization.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-108523 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-108523

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-108523 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108523

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Studio-Saelix Sencho git-sources Browse API Endpoint outboundTarget.ts server-side request forge

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/108xxx/CVE-2026-108523.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://vuldb.com/vuln/416189

    Supplemental source - vdb-entry, technical-description

  • Source reference

    Unverified legacy reference

    URL: https://vuldb.com/vuln/416189/cti

    Supplemental source - signature, permissions-required

  • Source reference

    Unverified legacy reference

    URL: https://vuldb.com/cve/CVE-2026-108523

    Supplemental source - third-party-advisory

  • Source reference

    Unverified legacy reference

    URL: https://vuldb.com/submit/893367

    Supplemental source - third-party-advisory

  • Source reference

    Unverified legacy reference

    URL: https://gist.github.com/jovair1994/93446c14d30a16313e830490d71bbd1d

    Supplemental source - exploit

  • Source reference

    Unverified legacy reference

    URL: https://github.com/Studio-Saelix/sencho/pull/1877

    Supplemental source - issue-tracking, patch

  • Source reference

    Unverified legacy reference

    URL: https://github.com/Studio-Saelix/sencho/commit/79b86ddcd4aefdd6941f098e35990ab397b13c72

    Supplemental source - patch

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.