A server-side request forgery (SSRF) vulnerability was identified in hyperledger-firefly FireFly up to version 1.4.0. The vulnerability resides in the ValidateOptions function within the file internal/events/webhooks/webhooks.go, part of the Webhook Subscription component. An attacker can manipulate the 'url' argument to trigger SSRF attacks remotely. The exploit has been publicly disclosed and is available for use. The vulnerability allows remote exploitation without requiring local access. The vendor was notified prior to public disclosure but did not respond. No patch or mitigation from the vendor has been confirmed at the time of disclosure. This affects blockchain infrastructure tooling used in enterprise and decentralized application environments.