CVE-2025-10695: Opensupports
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
Two unauthenticated diagnostic endpoints allow arbitrary backend-initiated network connections to an attacker‑supplied destination. Both endpoints are exposed with permission => 'any', enabling unauthenticated SSRF for internal network scanning and service interaction. This issue affects OpenSupports: 4.11.0.
Affected products
- Opensupports Opensupports: version 4.11.0 only
Published 2025-10-03. Last modified 2026-06-17.