Description
The Twilio integration webhook handler accepts any POST request without validating Twilio-s -X-Twilio-Signature-. When processing media messages, it fetches user-controlled URLs (-MediaUrlN- parameters) using HTTP requests that include the integration-s Twilio credentials in the -Authorization- header. An attacker can forge a webhook payload pointing to their own server and receive the victim-s -accountSID- and -authToken- in plaintext (base64-encoded Basic Auth), leading to full compromise of the Twilio account.
CVSS 8.2EPSS 0.156%Risk 0.83
View source- Published
- 2026-03-27 15:17:03
- Affected versions
- unknown
- Type
- Core software
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N