Flextype v1.0.0-alpha.3 Stored Fetch Shortcode Allows Server-Side Request Forgery
Flextype CMS v1.0.0-alpha.3's stored fetch shortcode enables server-side request forgery via attacker-controlled entry fields passed to fetch().
Flextype CMS v1.0.0-alpha.3 automatically processes attacker-controlled entry fields through its shortcode parser when global shortcode processing is enabled. The built-in fetch shortcode passes attacker-controlled resources to the server-side fetch() helper without sufficient destination restrictions. This enables stored server-side request forgery initiated from saved entry content. The issue was disclosed on the Full Disclosure mailing list on September 3, 2026.
26