Context-Inappropriate Capability
Medium
- Confidence
- 92% confidence
- Finding
- The heartbeat processes mailbox messages and unconditionally performs a POST to a user-controlled callback_url found in message metadata. That enables attacker-influenced outbound network requests, which can be abused for SSRF, internal service probing, or data exfiltration via the result payload. In this mailbox-processing context, the capability is more dangerous because incoming messages are effectively untrusted input and the code presents the webhook behavior as a normal automation step.
