top of page
perceptive_background_267k.jpg

A security vulnerability has been detected in jina-ai reader up to 1574bfd380d249c86c82db4dace0d9c8fe17e2b1. This issue affects the function isValidTLD of the f…

Published:

2 August 2026 at 22:00:00

Alert date:

3 August 2026 at 22:01:37

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Cloud & Virtualization

A server-side request forgery (SSRF) vulnerability has been identified in jina-ai reader up to commit 1574bfd380d249c86c82db4dace0d9c8fe17e2b1. The vulnerability exists in the isValidTLD function within the Crawler/Puppeteer component, specifically in the file /backend/functions/src/cloud-functions/crawler.ts. Remote attackers can exploit this flaw to perform SSRF attacks. A public exploit has been disclosed and may be actively used. The product uses a rolling release model, so no specific version numbers are provided for affected or patched releases. The vendor was notified prior to public disclosure but did not respond. This vulnerability poses a significant risk as SSRF can be used to pivot attacks into internal networks or cloud metadata services.

Technical details

Mitigation steps:

Affected products:

jina-ai reader

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page