


Perceptive Security
SOC/SIEM Consultancy

A vulnerability has been found in BidingCC BuildingAI up to 26.0.1. Impacted is the function uploadRemoteFile of the file packages/core/src/modules/upload/servi…
Published:
26 april 2026 om 22:00:00
Alert date:
27 april 2026 om 19:18:12
Source:
nvd.nist.gov
Web Technologies
A server-side request forgery (SSRF) vulnerability has been discovered in BidingCC BuildingAI up to version 26.0.1. The vulnerability affects the uploadRemoteFile function in the Remote Upload API component, specifically in the file-storage.service.ts file. The flaw can be exploited remotely by manipulating the url argument. A public exploit has been disclosed and the vulnerability has been reported to the project maintainers, but no response has been received yet. This allows attackers to potentially access internal resources or perform unauthorized network requests through the vulnerable application.
Technical details
Mitigation steps:
Affected products:
BidingCC BuildingAI
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-7065
https://github.com/BidingCC/BuildingAI/
https://github.com/BidingCC/BuildingAI/issues/110
https://vuldb.com/submit/798621
https://vuldb.com/vuln/359640
https://vuldb.com/vuln/359640/cti
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
