Server-side Request Forgery (SSRF) Affecting edx-enterprise package, versions [7.0.2, 7.0.6)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.3% (22nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Server-side Request Forgery (SSRF) vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PYTHON-EDXENTERPRISE-16431738
  • published6 May 2026
  • disclosed5 May 2026
  • creditKhaled M.Alshammri

Introduced: 5 May 2026

CVE-2026-42860  (opens in a new tab)
CWE-918  (opens in a new tab)

How to fix?

Upgrade edx-enterprise to version 7.0.6 or higher.

Overview

edx-enterprise is a Your project description goes here

Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) via the sync_provider_data function. An attacker can cause the server to make arbitrary HTTP requests to internal or external resources by supplying a crafted URL in the SAML metadata source field. This can lead to exposure of sensitive internal information, such as cloud instance metadata or internal APIs, and may allow further attacks such as credential theft or internal network scanning.

Note: This is only exploitable if the attacker has the Enterprise Admin role for an enterprise customer with a configured SAML Identity Provider.

Workaround

This vulnerability can be mitigated by enforcing network-level egress filtering to block outbound connections from the server to sensitive internal IP ranges.

CVSS Base Scores

version 4.0
version 3.1