
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-30834 is a Server-Side Request Forgery (SSRF) vulnerability in PinchTab's /download endpoint that allows unauthenticated attackers to make arbitrary requests to internal network services and local system files, with full response exfiltration. It affects PinchTab versions up to and including 0.7.6 (Go module github.com/pinchtab/pinchtab/cmd/pinchtab). The vulnerability was published on March 5, 2026, by researcher aleister1102, reviewed by GitHub on March 6, 2026, and published to the NVD on March 7, 2026. It carries a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory, PinchTab Advisory).
The root cause is improper input validation (CWE-918) in the GET /download?url= handler located in internal/handlers/download.go. The user-supplied url parameter is passed directly to chromedp.Navigate(dlURL) — a headless Chrome browser instance — without any validation or sanitization, as shown in the vulnerable code at line 78: if err := chromedp.Run(ctx, chromedp.Navigate(dlURL)); err != nil. Because the request is executed by a headless Chrome process, it can access local files via the file:// scheme, internal services bound to localhost or private network IPs, and cloud provider metadata endpoints (e.g., 169.254.169.254). The server then returns the full captured response body to the requester, enabling complete data exfiltration with no authentication required (GitHub Advisory, PinchTab Advisory).
Successful exploitation results in a high confidentiality impact with no integrity or availability impact. An unauthenticated attacker can read arbitrary local files (e.g., /etc/passwd, SSH keys, application secrets), probe and access internal network services not exposed externally, and retrieve cloud provider instance metadata including IAM credentials (e.g., AWS metadata at 169.254.169.254). In deployments where the PinchTab API is network-accessible, a compromised or malicious client can use this vulnerability as a pivot point to enumerate and attack internal infrastructure (GitHub Advisory, PinchTab Advisory).
A proof-of-concept exploit consisting of concrete curl commands is publicly available in the official security advisory, making exploitation trivial. No authentication is required, and attack complexity is low. The EPSS score is approximately 0.032% (0.000320), indicating a currently low but non-zero probability of exploitation in the wild. There is no evidence of active in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. Qualys has added detection for this vulnerability (detection ID 761789) (GitHub Advisory, PinchTab Advisory).
GET /download?url= endpoint, which accepts a user-controlled URL parameter without validation.file:// scheme to read sensitive local files:curl -X GET "http://<target>:9867/download?url=file:///etc/passwd"curl -X GET "http://<target>:9867/download?url=http://localhost:8080/internal-admin"curl -X GET "http://<target>:9867/download?url=http://169.254.169.254/latest/meta-data/iam/security-credentials/"169.254.169.254); unusual HTTP GET requests to port 9867 with url= parameters containing file://, http://localhost, or internal RFC-1918 addresses.GET /download?url=file://... or GET /download?url=http://localhost:... requests; headless Chrome process logs indicating navigation to file:// or internal URLs./etc/passwd, /etc/shadow, application config files) may be inferred from Chrome's access patterns in system audit logs (PinchTab Advisory).Upgrade PinchTab to version 0.7.7 or later, which patches the vulnerability by adding URL validation and sanitization to the /download handler. As an interim workaround, restrict network access to the PinchTab API (default port 9867) using firewall rules or network segmentation to prevent untrusted clients from reaching the endpoint. Avoid exposing the PinchTab API to untrusted networks even when authentication is enabled, as the vulnerability is exploitable by any authenticated user as well (GitHub Advisory, PinchTab Advisory).
The vulnerability was discussed on social media platforms including Mastodon and Bluesky shortly after disclosure. A technical write-up was published by Infinit Security at infinitsec.net covering the SSRF with full response exfiltration via the download handler. The Spanish national CERT (INCIBE-CERT) issued an early warning advisory for the vulnerability. OpenSUSE also published a security announcement referencing CVE-2026-30834 (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."