dataCycle-CORE Server-Side Request Forgery Vulnerability via State-Changing GET Endpoints

Vulnerability

A vulnerability in dataCycle-CORE versions prior to 25.07.3 allows for server-side request forgery (SSRF) by exploiting state-changing GET endpoints. The application fails to apply proper Cross-Site Request Forgery (CSRF) protections to GET requests, enabling attackers to manipulate application state on behalf of logged-in users. This can be achieved by embedding a link or redirecting to a vulnerable endpoint, such as 'watch_lists/:id/add_item?thing_id=...', which adds items to a watch list without requiring a CSRF token. Other GET mutation routes are also available, including user impersonation for authorized admins and changes to cache or translation states.

Impact

Exploitation of this vulnerability allows for unauthorized modification of application state, including adding items to watch lists and impersonating users with admin privileges.

Remediation

Users can upgrade to dataCycle-CORE version 26.06.08 to address this vulnerability.

Added: Jul 21, 2026, 12:47 AM
Updated: Jul 21, 2026, 12:47 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
6.4
remediation
0.0
relevance
9.9
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.