VALIDATED FINDING
Evidence attached
Server-Side Request Forgery in webhooks/receiver
SeverityHigh CVSS 3.18.6 Priority79 Confirmedvia replay
Untrusted caller-supplied URLs reach an internal egress without an allowlist. Replayed in a sandbox against a fresh authorised target — the same control was validated to fail twice.