A server-side request forgery (SSRF) vulnerability in...
Critical severity
Unreviewed
Published
Oct 17, 2025
to the GitHub Advisory Database
Description
Published by the National Vulnerability Database
Oct 17, 2025
Published to the GitHub Advisory Database
Oct 17, 2025
A server-side request forgery (SSRF) vulnerability in Illia Cloud illia-Builder before v4.8.5 allows authenticated users to send arbitrary requests to internal services via the API. An attacker can leverage this to enumerate open ports based on response discrepancies and interact with internal services.
References