PatchSiren

lightdash CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM lightdash CVE published 2026-08-20

CVE-2026-72846

Lightdash stores webhook URLs for scheduled deliveries and posts to them without proper validation, allowing SSRF attacks. A user can direct the server to issue POST requests to private, loopback, and link-local addresses. The vulnerability is mitigated in version 1.146.4 by routing clients through postSchedulerWebhook. This issue affects Lightdash users, administrators, and security teams, who should be [truncated]