PatchSiren

appsmithorg CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM appsmithorg CVE published 2026-04-02

CVE-2026-5418

A vulnerability was identified in Appsmith up to version 1.97, impacting the computeDisallowedHosts function in the WebClientUtils.java file. This issue allows for server-side request forgery and can be exploited remotely. The exploit is publicly available. Upgrading to version 1.99 is recommended. The vulnerability has a CVSS score of 5.5, indicating a medium severity level. Affected users should review [truncated]