CVE-2026-24736 | squidex up to 7.21.0 Webhook Configuration url server-side request forgery (GHSA-wxg2-953m-fg2w)
A vulnerability has been found in squidex up to 7.21.0 and classified as critical. Affected by this issue is some unknown functionality of the component Webhook Configuration. The manipulation of the argument url leads to server-side request forgery.
This vulnerability is uniquely identified as CVE-2026-24736. The attack is possible to be carried out remotely. No exploit exists.