PatchSiren

activepieces CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW activepieces CVE published 2026-06-21

CVE-2026-12813

CVE-2026-12813 is a server-side request forgery (SSRF) vulnerability detected in activepieces up to version 0.83.0. The vulnerability affects the handleUrlFile function in the /packages/server/engine/src/lib/variables/processors/file.ts file. This issue allows for remote exploitation and has a publicly available exploit. The CVSS score is 2.1, indicating a low severity. The vendor, Unknown Vendor, was con [truncated]