CVE-2026-41177: Ssrf Uri Localpath File Inclusion
The application reads a local file path derived from a URI's `LocalPath` or `AbsolutePath` without first evaluating an authorization or configuration check. When a generic URI handler attempts to support the `file://` scheme, attackers can supply a local path to induce Server-Side Request Forgery (SSRF) and Local File Inclusion (LFI). Validate the user's aut
greprules fetch cve-2026-41177-ssrf-uri-localpath-file-inclusion --engine opengrepDescription
The application reads a local file path derived from a URI's `LocalPath` or `AbsolutePath` without first evaluating an authorization or configuration check. When a generic URI handler attempts to support the `file://` scheme, attackers can supply a local path to induce Server-Side Request Forgery (SSRF) and Local File Inclusion (LFI). Validate the user's aut
Community feedback
0 rule-level signals from signed-in users.
- Useful reports
- 0
- Context false positives
- 0
- Metadata suggestions
- 0
Contextual precision
Aggregated from approved scan feedback. False-positive reports describe observed scan contexts, not a global rule verdict.
- Findings observed
- 0
- Projects
- 0
- Reporters
- 0
Precision details are collecting more signed-in reports before verdict counts or ratios are emphasized.
No approved finding verdicts yet.
No scan diagnostics reported yet.