CVE-2026-4528 | trueleaf ApiFlow 0.9.7 URL Validation http_proxy.service.ts validateUrlSecurity server-side request forgery
A vulnerability was found in trueleaf ApiFlow 0.9.7. It has been classified as critical. The impacted element is the function validateUrlSecurity of the file packages/server/src/service/proxy/http_proxy.service.ts of the component URL Validation Handler. This manipulation causes server-side request forgery.
This vulnerability is registered as CVE-2026-4528. Remote exploitation of the attack is possible. Furthermore, an exploit is available.