MegaParse 0.0.55 contains an unauthenticated server-side...
High severity
Unreviewed
Published
Sep 4, 2026
to the GitHub Advisory Database
•
Updated Sep 4, 2026
Description
Published by the National Vulnerability Database
Sep 4, 2026
Published to the GitHub Advisory Database
Sep 4, 2026
Last updated
Sep 4, 2026
MegaParse 0.0.55 contains an unauthenticated server-side request forgery vulnerability in the POST /v1/url endpoint that fetches caller-supplied URLs server-side. Attackers can supply internal service URLs or metadata endpoints without authentication to read their responses directly from the JSON response.
References