Common Weakness Enumeration

CWE-918

Allowed

Server-Side Request Forgery (SSRF)

Abstraction: Base · Status: Incomplete

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

6095 vulnerabilities reference this CWE, most recent first.

CVE-2026-104120 (GCVE-0-2026-104120)

Vulnerability from cvelistv5 – Published: 2026-10-02 02:15 – Updated: 2026-10-02 02:15
VLAI
Title
modelcontextprotocol mcp-server-fetch/mcp-server-everything Fetch Tool server.py fetch_url server-side request forgery
Summary
A security vulnerability has been detected in modelcontextprotocol mcp-server-fetch and mcp-server-everything up to 2026.6.4. Affected is the function fetch_url of the file mcp_server_fetch/server.py of the component Fetch Tool. The manipulation of the argument url/path leads to server-side request forgery. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance.
CWE
  • CWE-918 - Server-Side Request Forgery
References
URL Tags
https://vuldb.com/vuln/412764 vdb-entrytechnical-description
https://vuldb.com/vuln/412764/cti signaturepermissions-required
https://vuldb.com/cve/CVE-2026-104120 third-party-advisory
https://vuldb.com/submit/960099 third-party-advisory
https://github.com/modelcontextprotocol/servers/i… exploitissue-tracking
https://github.com/modelcontextprotocol/servers/p… issue-trackingpatch
Impacted products
Vendor Product Version
modelcontextprotocol mcp-server-fetch Affected: 2026.6.0
Affected: 2026.6.1
Affected: 2026.6.2
Affected: 2026.6.3
Affected: 2026.6.4
    cpe:2.3:a:modelcontextprotocol:mcp-server-fetch:*:*:*:*:*:*:*:*
Create a notification for this product.
modelcontextprotocol mcp-server-everything Affected: 2026.6.0
Affected: 2026.6.1
Affected: 2026.6.2
Affected: 2026.6.3
Affected: 2026.6.4
    cpe:2.3:a:modelcontextprotocol:mcp-server-everything:*:*:*:*:*:*:*:*
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "cna": {
      "affected": [
        {
          "cpes": [
            "cpe:2.3:a:modelcontextprotocol:mcp-server-fetch:*:*:*:*:*:*:*:*"
          ],
          "modules": [
            "Fetch Tool"
          ],
          "product": "mcp-server-fetch",
          "vendor": "modelcontextprotocol",
          "versions": [
            {
              "status": "affected",
              "version": "2026.6.0"
            },
            {
              "status": "affected",
              "version": "2026.6.1"
            },
            {
              "status": "affected",
              "version": "2026.6.2"
            },
            {
              "status": "affected",
              "version": "2026.6.3"
            },
            {
              "status": "affected",
              "version": "2026.6.4"
            }
          ]
        },
        {
          "cpes": [
            "cpe:2.3:a:modelcontextprotocol:mcp-server-everything:*:*:*:*:*:*:*:*"
          ],
          "modules": [
            "Fetch Tool"
          ],
          "product": "mcp-server-everything",
          "vendor": "modelcontextprotocol",
          "versions": [
            {
              "status": "affected",
              "version": "2026.6.0"
            },
            {
              "status": "affected",
              "version": "2026.6.1"
            },
            {
              "status": "affected",
              "version": "2026.6.2"
            },
            {
              "status": "affected",
              "version": "2026.6.3"
            },
            {
              "status": "affected",
              "version": "2026.6.4"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "reporter",
          "value": "geochen (VulDB User)"
        },
        {
          "lang": "en",
          "type": "coordinator",
          "value": "VulDB CNA Team"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "A security vulnerability has been detected in modelcontextprotocol mcp-server-fetch and mcp-server-everything up to 2026.6.4. Affected is the function fetch_url of the file mcp_server_fetch/server.py of the component Fetch Tool. The manipulation of the argument url/path leads to server-side request forgery. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "baseScore": 6.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
            "version": "4.0"
          }
        },
        {
          "cvssV3_1": {
            "baseScore": 7.3,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C",
            "version": "3.1"
          }
        },
        {
          "cvssV3_0": {
            "baseScore": 7.3,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C",
            "version": "3.0"
          }
        },
        {
          "cvssV2_0": {
            "baseScore": 7.5,
            "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:C",
            "version": "2.0"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-918",
              "description": "Server-Side Request Forgery",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-10-02T02:15:18.514Z",
        "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "shortName": "VulDB"
      },
      "references": [
        {
          "name": "VDB-412764 | modelcontextprotocol mcp-server-fetch/mcp-server-everything Fetch Tool server.py fetch_url server-side request forgery",
          "tags": [
            "vdb-entry",
            "technical-description"
          ],
          "url": "https://vuldb.com/vuln/412764"
        },
        {
          "name": "VDB-412764 | CTI Indicators (IOB, IOC, IOA)",
          "tags": [
            "signature",
            "permissions-required"
          ],
          "url": "https://vuldb.com/vuln/412764/cti"
        },
        {
          "name": "CVE-2026-104120 | CVE Analysis and Report",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://vuldb.com/cve/CVE-2026-104120"
        },
        {
          "name": "Submit #960099 | https://github.com/modelcontextprotocol/ servers 2026.6.4 Server-Side Request Forgery",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://vuldb.com/submit/960099"
        },
        {
          "tags": [
            "exploit",
            "issue-tracking"
          ],
          "url": "https://github.com/modelcontextprotocol/servers/issues/4492"
        },
        {
          "tags": [
            "issue-tracking",
            "patch"
          ],
          "url": "https://github.com/modelcontextprotocol/servers/pull/4890"
        }
      ],
      "timeline": [
        {
          "lang": "en",
          "time": "2026-10-01T00:00:00.000Z",
          "value": "Advisory disclosed"
        },
        {
          "lang": "en",
          "time": "2026-10-01T02:00:00.000Z",
          "value": "VulDB entry created"
        },
        {
          "lang": "en",
          "time": "2026-10-01T20:20:15.000Z",
          "value": "VulDB entry last update"
        }
      ],
      "title": "modelcontextprotocol mcp-server-fetch/mcp-server-everything Fetch Tool server.py fetch_url server-side request forgery",
      "x_generator": [
        "VulDB PVTS v202610"
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
    "assignerShortName": "VulDB",
    "cveId": "CVE-2026-104120",
    "datePublished": "2026-10-02T02:15:18.514Z",
    "dateReserved": "2026-10-01T18:15:10.419Z",
    "dateUpdated": "2026-10-02T02:15:18.514Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-103757 (GCVE-0-2026-103757)

Vulnerability from cvelistv5 – Published: 2026-10-01 10:42 – Updated: 2026-10-01 13:21
VLAI
Title
Budibase before 3.41.0 SSRF via uploadUrl in AI Table Generation
Summary
Budibase through 3.41.0 contains a server-side request forgery vulnerability in AI table generation because the uploadUrl function in packages/server/src/utilities/fileUtils.ts uses raw node-fetch instead of fetchWithBlacklist. Authenticated builder users can send a prompt to POST /api/ai/tables that places an internal URL in an attachment column, causing the server to fetch it and return a presigned object-storage URL containing the response, such as cloud metadata credentials.
SSVC
Exploitation: poc Automatable: no Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 13:21 UTC
CWE
  • CWE-918 - Server-Side Request Forgery (SSRF)
References
Impacted products
Vendor Product Version
Budibase budibase Affected: 0 , < 3.41.0 (semver)
Unaffected: 3.41.0 (semver)
    cpe:2.3:a:budibase:budibase:*:*:*:*:*:*:*:*
Create a notification for this product.
Date Public
2026-09-17 00:00
Credits
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-103757",
                "options": [
                  {
                    "Exploitation": "poc"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-10-01T13:21:24.130408Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-10-01T13:21:55.140Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "references": [
          {
            "tags": [
              "exploit"
            ],
            "url": "https://github.com/Budibase/budibase/security/advisories/GHSA-3c52-v5v2-3r56"
          }
        ],
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "packageURL": "pkg:npm/budibase",
          "product": "budibase",
          "vendor": "Budibase",
          "versions": [
            {
              "lessThan": "3.41.0",
              "status": "affected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "3.41.0",
              "versionType": "semver"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:a:budibase:budibase:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "3.41.0",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "reporter",
          "value": "sfwani"
        }
      ],
      "datePublic": "2026-09-17T00:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "value": "Budibase through 3.41.0 contains a server-side request forgery vulnerability in AI table generation because the uploadUrl function in packages/server/src/utilities/fileUtils.ts uses raw node-fetch instead of fetchWithBlacklist. Authenticated builder users can send a prompt to POST /api/ai/tables that places an internal URL in an attachment column, causing the server to fetch it and return a presigned object-storage URL containing the response, such as cloud metadata credentials."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "baseScore": 8.3,
            "baseSeverity": "HIGH",
            "privilegesRequired": "LOW",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "HIGH",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "NONE"
          },
          "format": "CVSS"
        },
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 7.7,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
            "version": "3.1"
          },
          "format": "CVSS"
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-918",
              "description": "Server-Side Request Forgery (SSRF)",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-10-01T10:42:25.919Z",
        "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "shortName": "VulnCheck"
      },
      "references": [
        {
          "name": "GitHub Security Advisory (GHSA-3c52-v5v2-3r56)",
          "tags": [
            "vendor-advisory"
          ],
          "url": "https://github.com/Budibase/budibase/security/advisories/GHSA-3c52-v5v2-3r56"
        },
        {
          "name": "VulnCheck Advisory: Budibase before 3.41.0 SSRF via uploadUrl in AI Table Generation",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://www.vulncheck.com/advisories/budibase-before-3.41.0-ssrf-via-uploadurl-in-ai-table-generation"
        }
      ],
      "title": "Budibase before 3.41.0 SSRF via uploadUrl in AI Table Generation",
      "x_generator": {
        "engine": "vulncheck-endgame"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
    "assignerShortName": "VulnCheck",
    "cveId": "CVE-2026-103757",
    "datePublished": "2026-10-01T10:42:25.919Z",
    "dateReserved": "2026-10-01T10:39:47.844Z",
    "dateUpdated": "2026-10-01T13:21:55.140Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-103542 (GCVE-0-2026-103542)

Vulnerability from cvelistv5 – Published: 2026-10-01 05:45 – Updated: 2026-10-01 05:45
VLAI
Title
formtools.org Form Tools AJAX Endpoint actions.php smart_fill server-side request forgery
Summary
A flaw has been found in formtools.org Form Tools up to 3.1.1. Impacted is the function smart_fill of the file /global/code/actions.php of the component AJAX Endpoint. This manipulation of the argument url causes server-side request forgery. The attack can be initiated remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
CWE
  • CWE-918 - Server-Side Request Forgery
References
Impacted products
Vendor Product Version
formtools.org Form Tools Affected: 3.1.0
Affected: 3.1.1
    cpe:2.3:a:form_tools:form_tools:*:*:*:*:*:*:*:*
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "cna": {
      "affected": [
        {
          "cpes": [
            "cpe:2.3:a:form_tools:form_tools:*:*:*:*:*:*:*:*"
          ],
          "modules": [
            "AJAX Endpoint"
          ],
          "product": "Form Tools",
          "vendor": "formtools.org",
          "versions": [
            {
              "status": "affected",
              "version": "3.1.0"
            },
            {
              "status": "affected",
              "version": "3.1.1"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "reporter",
          "value": "wenyouwen (VulDB User)"
        },
        {
          "lang": "en",
          "type": "coordinator",
          "value": "VulDB CNA Team"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "A flaw has been found in formtools.org Form Tools up to 3.1.1. Impacted is the function smart_fill of the file /global/code/actions.php of the component AJAX Endpoint. This manipulation of the argument url causes server-side request forgery. The attack can be initiated remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P",
            "version": "4.0"
          }
        },
        {
          "cvssV3_1": {
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:C",
            "version": "3.1"
          }
        },
        {
          "cvssV3_0": {
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:C",
            "version": "3.0"
          }
        },
        {
          "cvssV2_0": {
            "baseScore": 4,
            "vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:N/E:POC/RL:ND/RC:C",
            "version": "2.0"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-918",
              "description": "Server-Side Request Forgery",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-10-01T05:45:09.301Z",
        "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "shortName": "VulDB"
      },
      "references": [
        {
          "name": "VDB-412352 | formtools.org Form Tools AJAX Endpoint actions.php smart_fill server-side request forgery",
          "tags": [
            "vdb-entry",
            "technical-description"
          ],
          "url": "https://vuldb.com/vuln/412352"
        },
        {
          "name": "VDB-412352 | CTI Indicators (IOB, IOC, IOA)",
          "tags": [
            "signature",
            "permissions-required"
          ],
          "url": "https://vuldb.com/vuln/412352/cti"
        },
        {
          "name": "CVE-2026-103542 | CVE Analysis and Report",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://vuldb.com/cve/CVE-2026-103542"
        },
        {
          "name": "Submit #957909 | formtools.org / Form Tools project Form Tools Core 3.1.1 Server-Side Request Forgery",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://vuldb.com/submit/957909"
        },
        {
          "tags": [
            "issue-tracking"
          ],
          "url": "https://github.com/formtools/core/issues/958"
        },
        {
          "tags": [
            "exploit"
          ],
          "url": "https://github.com/wawyw/cve_report/blob/main/formtools_3.md"
        }
      ],
      "timeline": [
        {
          "lang": "en",
          "time": "2026-09-30T00:00:00.000Z",
          "value": "Advisory disclosed"
        },
        {
          "lang": "en",
          "time": "2026-09-30T02:00:00.000Z",
          "value": "VulDB entry created"
        },
        {
          "lang": "en",
          "time": "2026-09-30T21:12:57.000Z",
          "value": "VulDB entry last update"
        }
      ],
      "title": "formtools.org Form Tools AJAX Endpoint actions.php smart_fill server-side request forgery",
      "x_generator": [
        "VulDB PVTS v202610"
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
    "assignerShortName": "VulDB",
    "cveId": "CVE-2026-103542",
    "datePublished": "2026-10-01T05:45:09.301Z",
    "dateReserved": "2026-09-30T19:07:46.908Z",
    "dateUpdated": "2026-10-01T05:45:09.301Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-103530 (GCVE-0-2026-103530)

Vulnerability from cvelistv5 – Published: 2026-09-30 23:45 – Updated: 2026-10-01 14:23
VLAI
Title
decolua 9Router Search Endpoint ssrfGuard.js fetch server-side request forgery
Summary
A vulnerability was detected in decolua 9Router up to 0.5.55. The affected element is the function fetch of the file src/shared/utils/ssrfGuard.js of the component Search Endpoint. Performing a manipulation of the argument provider_options.baseUrl results in server-side request forgery. The attack can be initiated remotely. Applying a patch is the recommended action to fix this issue.
SSVC
Exploitation: none Automatable: yes Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 14:22 UTC
CWE
  • CWE-918 - Server-Side Request Forgery
References
Impacted products
Vendor Product Version
decolua 9Router Affected: 0.5.0
Affected: 0.5.1
Affected: 0.5.2
Affected: 0.5.3
Affected: 0.5.4
Affected: 0.5.5
Affected: 0.5.6
Affected: 0.5.7
Affected: 0.5.8
Affected: 0.5.9
Affected: 0.5.10
Affected: 0.5.11
Affected: 0.5.12
Affected: 0.5.13
Affected: 0.5.14
Affected: 0.5.15
Affected: 0.5.16
Affected: 0.5.17
Affected: 0.5.18
Affected: 0.5.19
Affected: 0.5.20
Affected: 0.5.21
Affected: 0.5.22
Affected: 0.5.23
Affected: 0.5.24
Affected: 0.5.25
Affected: 0.5.26
Affected: 0.5.27
Affected: 0.5.28
Affected: 0.5.29
Affected: 0.5.30
Affected: 0.5.31
Affected: 0.5.32
Affected: 0.5.33
Affected: 0.5.34
Affected: 0.5.35
Affected: 0.5.36
Affected: 0.5.37
Affected: 0.5.38
Affected: 0.5.39
Affected: 0.5.40
Affected: 0.5.41
Affected: 0.5.42
Affected: 0.5.43
Affected: 0.5.44
Affected: 0.5.45
Affected: 0.5.46
Affected: 0.5.47
Affected: 0.5.48
Affected: 0.5.49
Affected: 0.5.50
Affected: 0.5.51
Affected: 0.5.52
Affected: 0.5.53
Affected: 0.5.54
Affected: 0.5.55
    cpe:2.3:h:decolua:9router:*:*:*:*:*:*:*:*
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-103530",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-10-01T14:22:56.680757Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-10-01T14:23:03.729Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "cpes": [
            "cpe:2.3:h:decolua:9router:*:*:*:*:*:*:*:*"
          ],
          "modules": [
            "Search Endpoint"
          ],
          "product": "9Router",
          "vendor": "decolua",
          "versions": [
            {
              "status": "affected",
              "version": "0.5.0"
            },
            {
              "status": "affected",
              "version": "0.5.1"
            },
            {
              "status": "affected",
              "version": "0.5.2"
            },
            {
              "status": "affected",
              "version": "0.5.3"
            },
            {
              "status": "affected",
              "version": "0.5.4"
            },
            {
              "status": "affected",
              "version": "0.5.5"
            },
            {
              "status": "affected",
              "version": "0.5.6"
            },
            {
              "status": "affected",
              "version": "0.5.7"
            },
            {
              "status": "affected",
              "version": "0.5.8"
            },
            {
              "status": "affected",
              "version": "0.5.9"
            },
            {
              "status": "affected",
              "version": "0.5.10"
            },
            {
              "status": "affected",
              "version": "0.5.11"
            },
            {
              "status": "affected",
              "version": "0.5.12"
            },
            {
              "status": "affected",
              "version": "0.5.13"
            },
            {
              "status": "affected",
              "version": "0.5.14"
            },
            {
              "status": "affected",
              "version": "0.5.15"
            },
            {
              "status": "affected",
              "version": "0.5.16"
            },
            {
              "status": "affected",
              "version": "0.5.17"
            },
            {
              "status": "affected",
              "version": "0.5.18"
            },
            {
              "status": "affected",
              "version": "0.5.19"
            },
            {
              "status": "affected",
              "version": "0.5.20"
            },
            {
              "status": "affected",
              "version": "0.5.21"
            },
            {
              "status": "affected",
              "version": "0.5.22"
            },
            {
              "status": "affected",
              "version": "0.5.23"
            },
            {
              "status": "affected",
              "version": "0.5.24"
            },
            {
              "status": "affected",
              "version": "0.5.25"
            },
            {
              "status": "affected",
              "version": "0.5.26"
            },
            {
              "status": "affected",
              "version": "0.5.27"
            },
            {
              "status": "affected",
              "version": "0.5.28"
            },
            {
              "status": "affected",
              "version": "0.5.29"
            },
            {
              "status": "affected",
              "version": "0.5.30"
            },
            {
              "status": "affected",
              "version": "0.5.31"
            },
            {
              "status": "affected",
              "version": "0.5.32"
            },
            {
              "status": "affected",
              "version": "0.5.33"
            },
            {
              "status": "affected",
              "version": "0.5.34"
            },
            {
              "status": "affected",
              "version": "0.5.35"
            },
            {
              "status": "affected",
              "version": "0.5.36"
            },
            {
              "status": "affected",
              "version": "0.5.37"
            },
            {
              "status": "affected",
              "version": "0.5.38"
            },
            {
              "status": "affected",
              "version": "0.5.39"
            },
            {
              "status": "affected",
              "version": "0.5.40"
            },
            {
              "status": "affected",
              "version": "0.5.41"
            },
            {
              "status": "affected",
              "version": "0.5.42"
            },
            {
              "status": "affected",
              "version": "0.5.43"
            },
            {
              "status": "affected",
              "version": "0.5.44"
            },
            {
              "status": "affected",
              "version": "0.5.45"
            },
            {
              "status": "affected",
              "version": "0.5.46"
            },
            {
              "status": "affected",
              "version": "0.5.47"
            },
            {
              "status": "affected",
              "version": "0.5.48"
            },
            {
              "status": "affected",
              "version": "0.5.49"
            },
            {
              "status": "affected",
              "version": "0.5.50"
            },
            {
              "status": "affected",
              "version": "0.5.51"
            },
            {
              "status": "affected",
              "version": "0.5.52"
            },
            {
              "status": "affected",
              "version": "0.5.53"
            },
            {
              "status": "affected",
              "version": "0.5.54"
            },
            {
              "status": "affected",
              "version": "0.5.55"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "reporter",
          "value": "CAPT (VulDB User)"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "A vulnerability was detected in decolua 9Router up to 0.5.55. The affected element is the function fetch of the file src/shared/utils/ssrfGuard.js of the component Search Endpoint. Performing a manipulation of the argument provider_options.baseUrl results in server-side request forgery. The attack can be initiated remotely. Applying a patch is the recommended action to fix this issue."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "baseScore": 6.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X",
            "version": "4.0"
          }
        },
        {
          "cvssV3_1": {
            "baseScore": 7.3,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C",
            "version": "3.1"
          }
        },
        {
          "cvssV3_0": {
            "baseScore": 7.3,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C",
            "version": "3.0"
          }
        },
        {
          "cvssV2_0": {
            "baseScore": 7.5,
            "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:ND/RL:OF/RC:C",
            "version": "2.0"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-918",
              "description": "Server-Side Request Forgery",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-30T23:45:11.762Z",
        "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "shortName": "VulDB"
      },
      "references": [
        {
          "name": "VDB-412342 | decolua 9Router Search Endpoint ssrfGuard.js fetch server-side request forgery",
          "tags": [
            "vdb-entry",
            "technical-description"
          ],
          "url": "https://vuldb.com/vuln/412342"
        },
        {
          "name": "VDB-412342 | CTI Indicators (IOB, IOC, IOA)",
          "tags": [
            "signature",
            "permissions-required"
          ],
          "url": "https://vuldb.com/vuln/412342/cti"
        },
        {
          "name": "CVE-2026-103530 | CVE Analysis and Report",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://vuldb.com/cve/CVE-2026-103530"
        },
        {
          "name": "Submit #956865 | decolua 9router 0.5.55 Server-Side Request Forgery",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://vuldb.com/submit/956865"
        },
        {
          "tags": [
            "issue-tracking"
          ],
          "url": "https://github.com/decolua/9router/issues/3714"
        },
        {
          "tags": [
            "issue-tracking",
            "patch"
          ],
          "url": "https://github.com/decolua/9router/pull/3723"
        },
        {
          "tags": [
            "product"
          ],
          "url": "https://github.com/decolua/9router/"
        }
      ],
      "timeline": [
        {
          "lang": "en",
          "time": "2026-09-30T00:00:00.000Z",
          "value": "Advisory disclosed"
        },
        {
          "lang": "en",
          "time": "2026-09-30T02:00:00.000Z",
          "value": "VulDB entry created"
        },
        {
          "lang": "en",
          "time": "2026-09-30T21:11:51.000Z",
          "value": "VulDB entry last update"
        }
      ],
      "title": "decolua 9Router Search Endpoint ssrfGuard.js fetch server-side request forgery",
      "x_generator": [
        "VulDB PVTS v202610"
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
    "assignerShortName": "VulDB",
    "cveId": "CVE-2026-103530",
    "datePublished": "2026-09-30T23:45:11.762Z",
    "dateReserved": "2026-09-30T19:06:45.120Z",
    "dateUpdated": "2026-10-01T14:23:03.729Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-103291 (GCVE-0-2026-103291)

Vulnerability from cvelistv5 – Published: 2026-10-01 10:42 – Updated: 2026-10-01 10:42
VLAI
Title
Ghost 3.20.2 before 6.51.0 SSRF via image-size fetch
Summary
Ghost versions from 3.20.2 before 6.51.0 contain a server-side request forgery vulnerability in image dimension refetching that allows authenticated staff users to trigger outbound HTTP requests to arbitrary URLs. Attackers can point image cards at attacker-controlled hosts or internal network endpoints to access metadata services and internal resources unavailable from the public internet.
CWE
  • CWE-918 - Server-Side Request Forgery (SSRF)
References
Impacted products
Vendor Product Version
TryGhost Ghost Affected: 3.20.2 , < 6.51.0 (semver)
Unaffected: 6.51.0 (semver)
    cpe:2.3:a:ghost:ghost:*:*:*:*:*:*:*:*
Create a notification for this product.
Date Public
2026-09-09 00:00
Show details on NVD website

{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "packageURL": "pkg:npm/ghost",
          "product": "Ghost",
          "vendor": "TryGhost",
          "versions": [
            {
              "lessThan": "6.51.0",
              "status": "affected",
              "version": "3.20.2",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.51.0",
              "versionType": "semver"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:a:ghost:ghost:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.51.0",
                  "versionStartIncluding": "3.20.2",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "datePublic": "2026-09-09T00:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "value": "Ghost versions from 3.20.2 before 6.51.0 contain a server-side request forgery vulnerability in image dimension refetching that allows authenticated staff users to trigger outbound HTTP requests to arbitrary URLs. Attackers can point image cards at attacker-controlled hosts or internal network endpoints to access metadata services and internal resources unavailable from the public internet."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "privilegesRequired": "LOW",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "LOW",
            "subIntegrityImpact": "LOW",
            "userInteraction": "NONE",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "LOW"
          },
          "format": "CVSS"
        },
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.4,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "format": "CVSS"
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-918",
              "description": "Server-Side Request Forgery (SSRF)",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-10-01T10:42:24.553Z",
        "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "shortName": "VulnCheck"
      },
      "references": [
        {
          "name": "GitHub Security Advisory (GHSA-rrq6-9r3c-7w26)",
          "tags": [
            "vendor-advisory"
          ],
          "url": "https://github.com/TryGhost/Ghost/security/advisories/GHSA-rrq6-9r3c-7w26"
        },
        {
          "name": "VulnCheck Advisory: Ghost 3.20.2 before 6.51.0 SSRF via image-size fetch",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://www.vulncheck.com/advisories/ghost-3.20.2-before-6.51.0-ssrf-via-image-size-fetch"
        }
      ],
      "title": "Ghost 3.20.2 before 6.51.0 SSRF via image-size fetch",
      "x_generator": {
        "engine": "vulncheck-endgame"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
    "assignerShortName": "VulnCheck",
    "cveId": "CVE-2026-103291",
    "datePublished": "2026-10-01T10:42:24.553Z",
    "dateReserved": "2026-09-30T10:59:26.443Z",
    "dateUpdated": "2026-10-01T10:42:24.553Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-103287 (GCVE-0-2026-103287)

Vulnerability from cvelistv5 – Published: 2026-10-01 10:42 – Updated: 2026-10-01 10:42
VLAI
Title
Ghost 1.18.0 before 6.27.0 Server-Side Request Forgery via Webhook
Summary
Ghost versions 1.18.0 before 6.27.0 contain a server-side request forgery vulnerability in the webhooks feature that allows staff users to probe internal hosts. Attackers with staff privileges can craft webhook requests to access internal network resources from the Ghost server.
CWE
  • CWE-918 - Server-Side Request Forgery (SSRF)
References
Impacted products
Vendor Product Version
TryGhost Ghost Affected: 1.18.0 , < 6.27.0 (semver)
    cpe:2.3:a:ghost:ghost:*:*:*:*:*:*:*:*
Create a notification for this product.
Date Public
2026-08-11 00:00
Show details on NVD website

{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "packageURL": "pkg:npm/ghost",
          "product": "Ghost",
          "vendor": "TryGhost",
          "versions": [
            {
              "lessThan": "6.27.0",
              "status": "affected",
              "version": "1.18.0",
              "versionType": "semver"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:a:ghost:ghost:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.27.0",
                  "versionStartIncluding": "1.18.0",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "reporter",
          "value": "0xkakash1"
        },
        {
          "lang": "en",
          "type": "reporter",
          "value": "0xBassia"
        },
        {
          "lang": "en",
          "type": "reporter",
          "value": "l3tchupkt"
        },
        {
          "lang": "en",
          "type": "reporter",
          "value": "rooks00"
        },
        {
          "lang": "en",
          "type": "reporter",
          "value": "Wernerina"
        }
      ],
      "datePublic": "2026-08-11T00:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "value": "Ghost versions 1.18.0 before 6.27.0 contain a server-side request forgery vulnerability in the webhooks feature that allows staff users to probe internal hosts. Attackers with staff privileges can craft webhook requests to access internal network resources from the Ghost server."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "baseScore": 5.1,
            "baseSeverity": "MEDIUM",
            "privilegesRequired": "HIGH",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "NONE"
          },
          "format": "CVSS"
        },
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 2.7,
            "baseSeverity": "LOW",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "format": "CVSS"
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-918",
              "description": "Server-Side Request Forgery (SSRF)",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-10-01T10:42:21.818Z",
        "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "shortName": "VulnCheck"
      },
      "references": [
        {
          "name": "GitHub Security Advisory (GHSA-354h-gmhv-mr9c)",
          "tags": [
            "vendor-advisory"
          ],
          "url": "https://github.com/TryGhost/Ghost/security/advisories/GHSA-354h-gmhv-mr9c"
        },
        {
          "name": "VulnCheck Advisory: Ghost 1.18.0 before 6.27.0 Server-Side Request Forgery via Webhook",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://www.vulncheck.com/advisories/ghost-1.18.0-before-6.27.0-server-side-request-forgery-via-webhook"
        }
      ],
      "title": "Ghost 1.18.0 before 6.27.0 Server-Side Request Forgery via Webhook",
      "x_generator": {
        "engine": "vulncheck-endgame"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
    "assignerShortName": "VulnCheck",
    "cveId": "CVE-2026-103287",
    "datePublished": "2026-10-01T10:42:21.818Z",
    "dateReserved": "2026-09-30T10:59:26.443Z",
    "dateUpdated": "2026-10-01T10:42:21.818Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-103243 (GCVE-0-2026-103243)

Vulnerability from cvelistv5 – Published: 2026-09-30 14:48 – Updated: 2026-09-30 14:48
VLAI
Title
LightLLM through 1.2.0 Server-Side Request Forgery via multimodal endpoints
Summary
LightLLM through 1.2.0 fails to validate image_url and audio_url parameters in multimodal endpoints, allowing unauthenticated attackers to perform server-side request forgery. Attackers can supply arbitrary URLs to fetch internal resources, with vision model processing disclosing content or error responses revealing internal network topology.
CWE
  • CWE-918 - Server-Side Request Forgery (SSRF)
Impacted products
Vendor Product Version
ModelTC LightLLM Affected: 0 , ≤ 1.2.0 (semver)
Create a notification for this product.
Date Public
2026-09-30 00:00
Show details on NVD website

{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "packageURL": "pkg:github/ModelTC/lightllm",
          "product": "LightLLM",
          "repo": "https://github.com/ModelTC/lightllm",
          "vendor": "ModelTC",
          "versions": [
            {
              "lessThanOrEqual": "1.2.0",
              "status": "affected",
              "version": "0",
              "versionType": "semver"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "finder",
          "value": "Mingkai Yu"
        },
        {
          "lang": "en",
          "type": "finder",
          "value": "Jiapeng Li"
        },
        {
          "lang": "en",
          "type": "finder",
          "value": "Jiajia Liu"
        }
      ],
      "datePublic": "2026-09-30T00:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "value": "LightLLM through 1.2.0 fails to validate image_url and audio_url parameters in multimodal endpoints, allowing unauthenticated attackers to perform server-side request forgery. Attackers can supply arbitrary URLs to fetch internal resources, with vision model processing disclosing content or error responses revealing internal network topology."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "baseScore": 6.9,
            "baseSeverity": "MEDIUM",
            "privilegesRequired": "NONE",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "LOW",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "NONE"
          },
          "format": "CVSS"
        },
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.8,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "CHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N",
            "version": "3.1"
          },
          "format": "CVSS"
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-918",
              "description": "Server-Side Request Forgery (SSRF)",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-30T14:48:54.414Z",
        "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "shortName": "VulnCheck"
      },
      "references": [
        {
          "name": "GitHub Issue #1608",
          "tags": [
            "issue-tracking"
          ],
          "url": "https://github.com/ModelTC/LightLLM/issues/1608"
        },
        {
          "tags": [
            "technical-description"
          ],
          "url": "https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/utils/multimodal_utils.py#L82-L91"
        },
        {
          "tags": [
            "technical-description"
          ],
          "url": "https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/server/multimodal_params.py#L149"
        },
        {
          "tags": [
            "product"
          ],
          "url": "https://github.com/ModelTC/LightLLM"
        },
        {
          "name": "VulnCheck Advisory: LightLLM through 1.2.0 Server-Side Request Forgery via multimodal endpoints",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://www.vulncheck.com/advisories/lightllm-through-1.2.0-server-side-request-forgery-via-multimodal-endpoints"
        }
      ],
      "title": "LightLLM through 1.2.0 Server-Side Request Forgery via multimodal endpoints",
      "x_generator": {
        "engine": "vulncheck-endgame"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
    "assignerShortName": "VulnCheck",
    "cveId": "CVE-2026-103243",
    "datePublished": "2026-09-30T14:48:54.414Z",
    "dateReserved": "2026-09-30T10:52:32.248Z",
    "dateUpdated": "2026-09-30T14:48:54.414Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-103082 (GCVE-0-2026-103082)

Vulnerability from cvelistv5 – Published: 2026-10-01 10:40 – Updated: 2026-10-01 19:20 X_Open Source
VLAI
Title
WordPress LA-Studio Element Kit for Elementor plugin <= 1.6.2 - Server Side Request Forgery (SSRF) vulnerability
Summary
Server-Side Request Forgery (SSRF) vulnerability in LA-Studio LA-Studio Element Kit for Elementor lastudio-element-kit allows Server Side Request Forgery.This issue affects LA-Studio Element Kit for Elementor: from n/a through 1.6.2.
SSVC
Exploitation: none Automatable: yes Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 19:20 UTC
CWE
  • CWE-918 - Server-Side Request Forgery (SSRF)
References
Impacted products
Vendor Product Version
LA-Studio LA-Studio Element Kit for Elementor Affected: 0 , ≤ 1.6.2 (custom)
Create a notification for this product.
Date Public
2026-10-01 10:39
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-103082",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-10-01T19:20:27.285979Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-10-01T19:20:47.386Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "collectionURL": "https://wordpress.org/plugins",
          "defaultStatus": "unaffected",
          "packageName": "lastudio-element-kit",
          "product": "LA-Studio Element Kit for Elementor",
          "vendor": "LA-Studio",
          "versions": [
            {
              "changes": [
                {
                  "at": "1.6.3",
                  "status": "unaffected"
                }
              ],
              "lessThanOrEqual": "1.6.2",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "finder",
          "value": "JunHee CHO | Patchstack Bug Bounty Program"
        }
      ],
      "datePublic": "2026-10-01T10:39:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "Server-Side Request Forgery (SSRF) vulnerability in LA-Studio LA-Studio Element Kit for Elementor lastudio-element-kit allows Server Side Request Forgery.\u003cp\u003eThis issue affects LA-Studio Element Kit for Elementor: from n/a through 1.6.2.\u003c/p\u003e"
            }
          ],
          "value": "Server-Side Request Forgery (SSRF) vulnerability in LA-Studio LA-Studio Element Kit for Elementor lastudio-element-kit allows Server Side Request Forgery.This issue affects LA-Studio Element Kit for Elementor: from n/a through 1.6.2."
        }
      ],
      "impacts": [
        {
          "capecId": "CAPEC-664",
          "descriptions": [
            {
              "lang": "en",
              "value": "Server Side Request Forgery"
            }
          ]
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 7.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "CHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-918",
              "description": "Server-Side Request Forgery (SSRF)",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-10-01T10:40:12.139Z",
        "orgId": "21595511-bba5-4825-b968-b78d1f9984a3",
        "shortName": "Patchstack"
      },
      "references": [
        {
          "tags": [
            "vdb-entry"
          ],
          "url": "https://patchstack.com/database/wordpress/plugin/lastudio-element-kit/vulnerability/wordpress-la-studio-element-kit-for-elementor-plugin-1-6-2-server-side-request-forgery-ssrf-vulnerability?_s_id=cve"
        }
      ],
      "solutions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "Update the WordPress LA-Studio Element Kit for Elementor plugin to the latest available version (at least 1.6.3)."
            }
          ],
          "value": "Update the WordPress LA-Studio Element Kit for Elementor plugin to the latest available version (at least 1.6.3)."
        }
      ],
      "tags": [
        "x_open-source"
      ],
      "title": "WordPress LA-Studio Element Kit for Elementor plugin \u003c= 1.6.2 - Server Side Request Forgery (SSRF) vulnerability"
    }
  },
  "cveMetadata": {
    "assignerOrgId": "21595511-bba5-4825-b968-b78d1f9984a3",
    "assignerShortName": "Patchstack",
    "cveId": "CVE-2026-103082",
    "datePublished": "2026-10-01T10:40:12.139Z",
    "dateReserved": "2026-09-30T00:15:58.645Z",
    "dateUpdated": "2026-10-01T19:20:47.386Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-102983 (GCVE-0-2026-102983)

Vulnerability from cvelistv5 – Published: 2026-09-30 14:32 – Updated: 2026-09-30 16:24
VLAI
Title
Astro: Netlify Image CDN allowlist bypass enables SSRF
Summary
Astro is a web framework for content-driven websites. From 5.2.0 until 8.2.4, the @astrojs/netlify adapter generates regular expressions for Netlify Image CDN remote-image allowlists without anchoring them to the beginning of the URL. Because Netlify evaluates these expressions with RegExp.test(), an allowed origin appearing only in a source URL's path or query can satisfy image.domains or image.remotePatterns while the URL's actual host remains attacker-controlled. An unauthenticated request to the public /.netlify/images endpoint can therefore cause the Image CDN to request attacker-selected URLs and may probe or reach internal services. Netlify egress protections may constrain reachable targets, and image transformation limits direct response exfiltration; no confidentiality or integrity impact has been demonstrated. This issue is fixed in version 8.2.4.
SSVC
Exploitation: none Automatable: no Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-30 16:22 UTC
CWE
  • CWE-625 - Permissive Regular Expression
  • CWE-918 - Server-Side Request Forgery (SSRF)
Impacted products
Vendor Product Version
withastro astro Affected: >= 5.2.0, < 8.2.4
Create a notification for this product.
@astrojs netlify Affected: >= 5.2.0, < 8.2.4
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-102983",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-30T16:22:22.386566Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-30T16:24:47.048Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "astro",
          "vendor": "withastro",
          "versions": [
            {
              "status": "affected",
              "version": "\u003e= 5.2.0, \u003c 8.2.4"
            }
          ]
        },
        {
          "product": "netlify",
          "vendor": "@astrojs",
          "versions": [
            {
              "status": "affected",
              "version": "\u003e= 5.2.0, \u003c 8.2.4"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "Astro is a web framework for content-driven websites. From 5.2.0 until 8.2.4, the @astrojs/netlify adapter generates regular expressions for Netlify Image CDN remote-image allowlists without anchoring them to the beginning of the URL. Because Netlify evaluates these expressions with RegExp.test(), an allowed origin appearing only in a source URL\u0027s path or query can satisfy image.domains or image.remotePatterns while the URL\u0027s actual host remains attacker-controlled. An unauthenticated request to the public /.netlify/images endpoint can therefore cause the Image CDN to request attacker-selected URLs and may probe or reach internal services. Netlify egress protections may constrain reachable targets, and image transformation limits direct response exfiltration; no confidentiality or integrity impact has been demonstrated. This issue is fixed in version 8.2.4."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "attackComplexity": "LOW",
            "attackRequirements": "PRESENT",
            "attackVector": "NETWORK",
            "baseScore": 6.3,
            "baseSeverity": "MEDIUM",
            "privilegesRequired": "NONE",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "LOW",
            "vulnConfidentialityImpact": "NONE",
            "vulnIntegrityImpact": "NONE"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-625",
              "description": "CWE-625: Permissive Regular Expression",
              "lang": "en",
              "type": "CWE"
            }
          ]
        },
        {
          "descriptions": [
            {
              "cweId": "CWE-918",
              "description": "CWE-918: Server-Side Request Forgery (SSRF)",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-30T14:33:11.551Z",
        "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "shortName": "GitHub_M"
      },
      "references": [
        {
          "name": "https://github.com/withastro/astro/security/advisories/GHSA-4233-jc72-56c5",
          "tags": [
            "x_refsource_CONFIRM"
          ],
          "url": "https://github.com/withastro/astro/security/advisories/GHSA-4233-jc72-56c5"
        },
        {
          "name": "https://github.com/withastro/astro/pull/17752",
          "tags": [
            "x_refsource_MISC"
          ],
          "url": "https://github.com/withastro/astro/pull/17752"
        },
        {
          "name": "https://github.com/withastro/astro/commit/e362d4cf540b27730482455c8fc02efe57d16702",
          "tags": [
            "x_refsource_MISC"
          ],
          "url": "https://github.com/withastro/astro/commit/e362d4cf540b27730482455c8fc02efe57d16702"
        },
        {
          "name": "https://github.com/withastro/astro/releases/tag/@astrojs/netlify@8.2.4",
          "tags": [
            "x_refsource_MISC"
          ],
          "url": "https://github.com/withastro/astro/releases/tag/@astrojs/netlify@8.2.4"
        }
      ],
      "source": {
        "advisory": "GHSA-4233-jc72-56c5",
        "discovery": "UNKNOWN"
      },
      "title": "Astro: Netlify Image CDN allowlist bypass enables SSRF"
    }
  },
  "cveMetadata": {
    "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
    "assignerShortName": "GitHub_M",
    "cveId": "CVE-2026-102983",
    "datePublished": "2026-09-30T14:32:03.861Z",
    "dateReserved": "2026-09-29T20:46:08.333Z",
    "dateUpdated": "2026-09-30T16:24:47.048Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-102904 (GCVE-0-2026-102904)

Vulnerability from cvelistv5 – Published: 2026-09-29 20:47 – Updated: 2026-09-30 20:07
VLAI
Title
JupyterLab: Argument injection in JupyterLab extension uninstall exposes server-readable files and internal URLs
Summary
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From JupyterLab 4.0.0 until 4.5.11 and 4.6.4, the PyPI Extension Manager uninstall request reaches ExtensionHandler.post, which validates extension names for installation but passes uninstall names to PyPIExtensionManager.uninstall and python -m pip uninstall without rejecting option-like values. The security impact requires that the PyPI Extension Manager is enabled, the account can call the extension API, and kernels and terminals are disabled or delegated to remote hosts; otherwise the user can already read files and make outbound requests directly. An authenticated user with extension API access can supply a pip requirements option to make the server read a local file or fetch an internal URL, and reflected parse errors can return the first unparsable line or response content. A pip log option can also create or corrupt a chosen path with pip-generated log text, but the requester cannot select an arbitrary disclosed line or arbitrary file content, and the injection does not add code execution or availability impact beyond ordinary package removal. This issue is fixed in JupyterLab 4.5.11 and 4.6.4.
SSVC
Exploitation: none Automatable: no Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-30 20:06 UTC
CWE
  • CWE-88 - Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
  • CWE-209 - Generation of Error Message Containing Sensitive Information
  • CWE-918 - Server-Side Request Forgery (SSRF)
Impacted products
Vendor Product Version
jupyterlab jupyterlab Affected: >= 4.0.0, < 4.5.11
Affected: >= 4.6.0, < 4.6.4
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-102904",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-30T20:06:56.346526Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-30T20:07:08.531Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "jupyterlab",
          "vendor": "jupyterlab",
          "versions": [
            {
              "status": "affected",
              "version": "\u003e= 4.0.0, \u003c 4.5.11"
            },
            {
              "status": "affected",
              "version": "\u003e= 4.6.0, \u003c 4.6.4"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From JupyterLab 4.0.0 until 4.5.11 and 4.6.4, the PyPI Extension Manager uninstall request reaches ExtensionHandler.post, which validates extension names for installation but passes uninstall names to PyPIExtensionManager.uninstall and python -m pip uninstall without rejecting option-like values. The security impact requires that the PyPI Extension Manager is enabled, the account can call the extension API, and kernels and terminals are disabled or delegated to remote hosts; otherwise the user can already read files and make outbound requests directly. An authenticated user with extension API access can supply a pip requirements option to make the server read a local file or fetch an internal URL, and reflected parse errors can return the first unparsable line or response content. A pip log option can also create or corrupt a chosen path with pip-generated log text, but the requester cannot select an arbitrary disclosed line or arbitrary file content, and the injection does not add code execution or availability impact beyond ordinary package removal. This issue is fixed in JupyterLab 4.5.11 and 4.6.4."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
            "version": "3.1"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-88",
              "description": "CWE-88: Improper Neutralization of Argument Delimiters in a Command (\u0027Argument Injection\u0027)",
              "lang": "en",
              "type": "CWE"
            }
          ]
        },
        {
          "descriptions": [
            {
              "cweId": "CWE-209",
              "description": "CWE-209: Generation of Error Message Containing Sensitive Information",
              "lang": "en",
              "type": "CWE"
            }
          ]
        },
        {
          "descriptions": [
            {
              "cweId": "CWE-918",
              "description": "CWE-918: Server-Side Request Forgery (SSRF)",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-29T20:47:43.290Z",
        "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "shortName": "GitHub_M"
      },
      "references": [
        {
          "name": "https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-3325-v43h-43rv",
          "tags": [
            "x_refsource_CONFIRM"
          ],
          "url": "https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-3325-v43h-43rv"
        },
        {
          "name": "https://github.com/jupyterlab/jupyterlab/commit/a274a8276b9185d03efd4c3c20713d3137ac49e6",
          "tags": [
            "x_refsource_MISC"
          ],
          "url": "https://github.com/jupyterlab/jupyterlab/commit/a274a8276b9185d03efd4c3c20713d3137ac49e6"
        },
        {
          "name": "https://github.com/jupyterlab/jupyterlab/commit/e277bc958e737130ac47b6c5078d08b29298828f",
          "tags": [
            "x_refsource_MISC"
          ],
          "url": "https://github.com/jupyterlab/jupyterlab/commit/e277bc958e737130ac47b6c5078d08b29298828f"
        },
        {
          "name": "https://github.com/jupyterlab/jupyterlab/releases/tag/v4.5.11",
          "tags": [
            "x_refsource_MISC"
          ],
          "url": "https://github.com/jupyterlab/jupyterlab/releases/tag/v4.5.11"
        },
        {
          "name": "https://github.com/jupyterlab/jupyterlab/releases/tag/v4.6.4",
          "tags": [
            "x_refsource_MISC"
          ],
          "url": "https://github.com/jupyterlab/jupyterlab/releases/tag/v4.6.4"
        }
      ],
      "source": {
        "advisory": "GHSA-3325-v43h-43rv",
        "discovery": "UNKNOWN"
      },
      "title": "JupyterLab: Argument injection in JupyterLab extension uninstall exposes server-readable files and internal URLs"
    }
  },
  "cveMetadata": {
    "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
    "assignerShortName": "GitHub_M",
    "cveId": "CVE-2026-102904",
    "datePublished": "2026-09-29T20:47:43.290Z",
    "dateReserved": "2026-09-29T17:34:42.744Z",
    "dateUpdated": "2026-09-30T20:07:08.531Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

No mitigation information available for this CWE.

CAPEC-664: Server Side Request Forgery

An adversary exploits improper input validation by submitting maliciously crafted input to a target application running on a server, with the goal of forcing the server to make a request either to itself, to web services running in the server’s internal network, or to external third parties. If successful, the adversary’s request will be made with the server’s privilege level, bypassing its authentication controls. This ultimately allows the adversary to access sensitive data, execute commands on the server’s network, and make external requests with the stolen identity of the server. Server Side Request Forgery attacks differ from Cross Site Request Forgery attacks in that they target the server itself, whereas CSRF attacks exploit an insecure user authentication mechanism to perform unauthorized actions on the user's behalf.