CVE-2024-51408: Appsmith

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

AppSmith Community 1.8.3 before 1.46 allows SSRF via New DataSource for application/json requests to 169.254.169.254 to retrieve AWS metadata credentials.

Affected products

  • Appsmith Appsmith: from 1.8.3, before 1.46 (fixed in 1.46)

Published 2024-11-04. Last modified 2026-06-17.