# Server-side request forgery vulnerability

**URL:** https://meta.discourse.org/t/server-side-request-forgery-vulnerability/186996
**Category:** Support
**Created:** [April 15, 2021, 6:34pm UTC](https://meta.discourse.org/t/server-side-request-forgery-vulnerability/186996 "2021-04-15T18:34:22Z")
**Posts on this page:** 1
**Showing post:** 2

<div class="post-metadata">

### Author: ![supermathie](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/supermathie/32/507518_2.png) [@supermathie](https://meta.discourse.org/u/supermathie)
#### Post date: [April 15, 2021, 6:55pm UTC](https://meta.discourse.org/t/server-side-request-forgery-vulnerability/186996/2 "2021-04-15T18:55:21Z")

</div>

It appears to be that what they’re talking about is our [oneboxing functionality](https://meta.discourse.org/t/rich-link-previews-with-onebox/98088).

> [@Digital-Larry](#):
>
> A server-side request forgery vulnerability

It’s not a vulnerability; it’s intended behaviour. If a URL is posted to a Discourse forum, an outbound request is done to attempt to retrieve metadata to construct a onebox.

This kind of report appears to be part of a low-effort scan of websites for generic “vulnerabilities” since they are not familiar with how the software they are testing works.

If they _do_ have any findings we encourage them to submit them via our [HackerOne program](https://hackerone.com/discourse) bug bounty program.

If you have any further concerns we’d be happy to address them.

> [@Digital-Larry](#):
>
> I forwarded this to Discourse support in February 2021

I don’t have any record of messages from this email address but we’ll investigate to see why we didn’t receive it.

---

_[View the full topic](https://meta.discourse.org/t/server-side-request-forgery-vulnerability/186996)._
