Rebuild v3.7.7 was discovered to contain a Server-Side Request Forgery (SSRF) via the type parameter in the com.rebuild.web.admin.rbstore.RBStoreController#loadDataIndex method.
https://github.com/RacerZ-fighting/rebuild-vulns/blob/main/rebuild%203.7.7.md
https://github.com/RacerZ-fighting/CVE-vulns/blob/main/rebuild%203.7.7.md