PatchSiren

Studio-Saelix CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW Studio-Saelix CVE published 2026-10-11

CVE-2026-108521

A vulnerability was found in Studio-Saelix Sencho up to 0.97.1, affecting the function isValidRemoteUrl of the file backend/src/utils/validation.ts of the component Add Remote Node API Endpoint. This issue leads to server-side request forgery and can be executed remotely. The vulnerability allows an authenticated user with node-management permission to configure the node API URL and initiate server-side r [truncated]