GHSA-hj6f-7hp7-xg69
Mautic vulnerable to SSRF via webhook function
Quick fix
GHSA-hj6f-7hp7-xg69 — mautic/core: upgrade to the fixed version with the command below.
composer require mautic/core:^4.4.17Details
### Summary Users with webhook permissions can conduct SSRF via webhooks. If they have permission to view the webhook logs, the (partial) request response is also disclosed
### Details When sending webhooks, the destination is not validated, causing SSRF.
### Impact Bypass of firewalls to interact with internal services. See https://owasp.org/Top10/A10_2021-Server-Side_Request_Forgery_%28SSRF%29/ for more potential impact.
### Resources https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html for more information on SSRF and its fix
Are you affected?
Enter the version of the package you're using.
Affected packages
5.0.0-alphaFixed in: 5.2.8composer require mautic/core:^5.2.86.0.0-alphaFixed in: 6.0.5composer require mautic/core:^6.0.5References
- https://github.com/mautic/mautic/security/advisories/GHSA-hj6f-7hp7-xg69[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2025-9821[ADVISORY]
- https://github.com/mautic/mautic/commit/6084f6de4c88d1aeb5f6c73ea4fe1b09c98ea52b[WEB]
- https://github.com/mautic/mautic/commit/dc5bb1466c9a48fd34768dc8ff5888716b2916ba[WEB]
- https://github.com/mautic/mautic[PACKAGE]