CVE-2026-33619: 
vulnerability analysis and mitigation

Overview

CVE-2026-33619 is a Server-Side Request Forgery (SSRF) vulnerability in PinchTab's optional task scheduler webhook delivery path. Affecting PinchTab versions up to and including v0.8.3, the flaw allows an attacker to cause the PinchTab server to issue outbound HTTP POST requests to attacker-controlled destinations, including internal or private network targets. The advisory was published on March 22, 2026, and a patch was released in v0.8.4. It carries a CVSS v3.1 base score of 5.5 (Moderate) per NVD, though the GitHub advisory scores it at 4.1 (GitHub Advisory, Red Hat CVE).

Technical details

The root cause is CWE-918 (Server-Side Request Forgery), stemming from two related deficiencies in internal/scheduler/webhook.go and internal/scheduler/task.go. In v0.8.3, the sendWebhook() function validated only the URL scheme (http/https) before dispatching outbound requests, without resolving the hostname or rejecting loopback, private, link-local, or other non-public IP ranges. Additionally, the SubmitRequest.Validate() method in task.go did not validate the user-supplied callbackUrl field at task submission time, allowing unsafe URLs to flow directly into webhook delivery. The default http.Client was used, meaning HTTP redirects were followed without re-validation, enabling an attacker-controlled external endpoint to redirect the server to a second internal destination (GitHub Advisory).

Impact

Successful exploitation enables blind SSRF from the PinchTab server to any HTTP(S) target reachable from the server's network, including internal services, metadata endpoints (e.g., cloud instance metadata at 169.254.169.254), and other private infrastructure. Because the webhook is a fixed outbound POST and the response body is not returned to the attacker via the task API, direct confidentiality impact is limited; however, there is a low-integrity risk where internal services accepting unauthenticated POST requests could be triggered to perform state-changing actions. The practical risk is reduced in the default local-first deployment model but is elevated in network-exposed or tokenless deployments (GitHub Advisory).

Exploitability

A proof-of-concept exploit consisting of step-by-step curl commands is publicly available in the GitHub security advisory, demonstrating task submission with a malicious callbackUrl and confirmation of outbound server-side delivery (GitHub Advisory). There is no evidence of in-the-wild exploitation at this time. The EPSS score is 0.023% (very low probability of exploitation in the near term). Exploitation requires the optional scheduler to be enabled (off by default) and, in token-protected deployments, possession of the master API token; tokenless deployments lower the barrier further. The vulnerability is detected by Qualys scanner (detection ID 761875) and is not listed in the CISA KEV catalog.

Exploitation steps

  1. Reconnaissance: Identify a PinchTab instance (default port 9867) exposed on the network. Determine whether the scheduler is enabled by checking configuration or attempting task submission.
  2. Enable scheduler (if needed): If the scheduler is disabled, and the attacker holds the master API token, enable it via curl -s -X PUT http://TARGET:9867/api/config -H "Authorization: Bearer <TOKEN>" -H "Content-Type: application/json" -d '{"scheduler":{"enabled":true}}' and restart PinchTab.
  3. Submit malicious task: Send a POST request to /tasks with an attacker-controlled callbackUrl pointing to an internal target or an attacker-controlled listener: curl -s -X POST http://TARGET:9867/tasks -H "Authorization: Bearer <TOKEN>" -H "Content-Type: application/json" -d '{"agentId": "poc-agent", "action": "navigate", "params": {"url": "https://example.com"}, "callbackUrl": "http://169.254.169.254/latest/meta-data/"}'
  4. Wait for terminal state: The task will reach a terminal state (e.g., failed due to missing tabId), triggering webhook delivery to the specified callbackUrl.
  5. Observe outbound request: Poll the attacker-controlled receiver or internal service logs to confirm the PinchTab server issued an outbound POST, including task snapshot payload and PinchTab-specific headers, originating from the server's egress IP (GitHub Advisory).

Indicators of compromise

  • Network: Unexpected outbound HTTP POST requests from the PinchTab server (default port 9867 egress) to internal IP ranges (RFC 1918: 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16), loopback addresses, or cloud metadata endpoints (e.g., 169.254.169.254); outbound connections to external webhook receiver services (e.g., webhook.site) from the PinchTab process.
  • Logs: PinchTab server logs showing POST /tasks requests with callbackUrl values pointing to internal or non-public addresses; webhook delivery log entries referencing unexpected destinations.
  • Process: Unusual outbound HTTP connections initiated by the PinchTab Go process to internal network hosts or metadata services not consistent with normal browser automation activity (GitHub Advisory).

Mitigation and workarounds

Upgrade PinchTab to version 0.8.4 or later, which resolves the issue by validating callbackUrl at task submission time, resolving hostnames before dispatch, rejecting non-public IP ranges (loopback, private, link-local, multicast), pinning delivery to validated IPs, and disabling redirect following (GitHub Release v0.8.4, GitHub Advisory). If immediate patching is not possible, disable the optional scheduler component if it is not required. Additionally, apply network segmentation and firewall rules to restrict outbound HTTP access from the PinchTab server to sensitive internal and private network ranges, and ensure token-based authentication is enforced to limit who can submit tasks.

Community reactions

The vulnerability was reported by security researcher mean3374 and the advisory was published by PinchTab maintainer luigi-agosti on March 22, 2026 (GitHub Advisory). A brief community blog post was published at infinitsec.net noting the SSRF in the task scheduler. No significant broader media coverage or notable social media discussion has been identified beyond standard CVE aggregator entries.

Additional resources


Source: This report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management