CVE-2026-7084Disclosure

LOWCVSS 2.1 · LOW

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was found in HBAI-Ltd Toonflow-app up to 1.1.1. This affects the function fetch of the file src/routes/setting/vendorConfig/getCodeByLink.ts of the component getCodeByLink Endpoint. The manipulation of the argument Link results in server-side request forgery. The attack may be performed from remote. The exploit has been made public and could be used. There is ongoing doubt regarding the real existence of this vulnerability. The vendor explains in a reply to the issue report, that "[t]he /getCodeByLink interface is used to obtain TS code and run it locally. It is inherently a high-risk interface, and users must clearly understand the risks before requesting to use it."

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-27: 3Technical Details · 2026-04-27: 104-27
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    General

    CVE-2026-7084 A vulnerability was found in HBAI-Ltd Toonflow-app up to 1.1.1. This affects the function fetch of the file src/routes/setting/vendorConfig/getCodeByLink.ts of the comp… https://www.cve.org/CVERecord?id=CVE-2026-7084

    Post summary

    The post merely cites CVE‑2026‑7084 as affecting a specific function in HBAI‑Ltd's Toonflow‑app up to version 1.1.1, but offers no further technical detail, exploit code, or remediation information.

    0000097
    57.3K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-7084 📊 Severity: 6.3 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-7084 #CVE-2026-7084 #CVE #Medium #CyberSecurity #InfoSec https://t.co/nKPVVftoBL

    Post summary

    The tweet announces the discovery of CVE-2026-7084 with a medium severity score, but provides no details on exploitation methods, mitigation, or technical specifics.

    0000048
    141 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7084 Server-Side Request Forgery in HBAI-Ltd Toonflow-app Up to 1.1.1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7084

    Post summary

    The text announces an SSRF vulnerability (CVE‑2026‑7084) affecting Toonflow‑app up to version 1.1.1, providing technical details but no exploitation or patch information.

    0000047
    4.0K followersView on X

Explore more