webhook_url is unvalidated: server-side POST with attacker-chosen headers to any host (SSRF) #2
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
api_link_create_or_updaterequiressuccess_urlto start withhttps://(views_api.py:155-163) but applies no check at all towebhook_url. On every settled paymentsend_webhook(tasks.py:56-82) POSTs to that URL withheaders=json.loads(pay_link.webhook_headers), both creator-controlled. The transport RPCs (transport_rpcs.py:44-51,:86-105) expose the same fields. On a multi-tenant instance with open signup (aio-demo), any account holder with their own wallet admin key can aim the lnbits process athttp://169.254.169.254/,http://localhost:<port>/or anything on the docker network (nostrrelay, bunker, LND REST) and trigger the request by paying their own link. lnbits core has no SSRF helper to reuse.Fix direction: on create/update (HTTP and transport, via a shared validator) require
https://forwebhook_url, resolve the host and reject loopback, link-local, private and metadata ranges; consider an operator-level egress allow-list. Test:webhook_url = "http://169.254.169.254/"and"http://localhost:5000/"are rejected at create time.Found during reforge run #1 (sandbox lnurlp#5).