OpenMAIC vulnerability

OpenMAIC before 1.0.1 skips server-side request forgery validation in non-production builds, allowing unauthenticated attackers to reach cloud instance metadata services. Attackers can supply arbitrary provider URLs via the x-base-url header or baseUrl parameter to access sensitive cloud credentials and metadata.

Published 6 Sep 2026Updated 6 Sep 20266 sources
CVSS 9.0

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.