An open redirect vulnerability was identified that allows user-controlled URLs to be supplied to backend workflows without sufficient validation. When combined with the log export callback functionality, this results in a server-side request forgery (SSRF) condition in which a backend worker performs HTTP requests to arbitrary destinations supplied by an authenticated user.