CWE-918
AllowedServer-Side Request Forgery (SSRF)
Abstraction: Base · Status: Incomplete
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
6243 vulnerabilities reference this CWE, most recent first.
GHSA-VMH2-9R6C-H7Q4
Vulnerability from github – Published: 2026-09-10 15:33 – Updated: 2026-10-02 15:31OpenPanel is an analytics platform. In all versions (no patched release available at time of publication), the data importer fetches a caller-supplied URL with plain fetch instead of the project's existing SSRF guard (apps/api/src/utils/safe-fetch.ts). In packages/importer/src/providers/umami.ts, parseRemoteFile calls fetch() on config.fileUrl, which is validated only by z.string().url(), so values such as http://127.0.0.1:9911/ or http://169.254.169.254/latest/meta-data/ are accepted; the shared createFileImportConfig factory gives the plausible provider the same field. An authenticated organization member — including a default 'member' with no project_access rows, for whom the intended access-level check is skipped because getProjectAccess returns boolean true rather than a level object — can therefore make the server connect to any address reachable from it. The resulting HTTP status and status text are persisted as Import.errorMessage and returned by import.get to the same user, providing a scanning oracle for internal hosts, ports and paths; if an internal response parses as Umami CSV, its rows are ingested as events and become readable in the attacker's analytics views.
{
"affected": [],
"aliases": [
"CVE-2026-88892"
],
"database_specific": {
"cwe_ids": [
"CWE-918"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-09-10T14:17:18Z",
"severity": "MODERATE"
},
"details": "OpenPanel is an analytics platform. In all versions (no patched release available at time of publication), the data importer fetches a caller-supplied URL with plain fetch instead of the project\u0027s existing SSRF guard (apps/api/src/utils/safe-fetch.ts). In packages/importer/src/providers/umami.ts, parseRemoteFile calls fetch() on config.fileUrl, which is validated only by z.string().url(), so values such as http://127.0.0.1:9911/ or http://169.254.169.254/latest/meta-data/ are accepted; the shared createFileImportConfig factory gives the plausible provider the same field. An authenticated organization member \u2014 including a default \u0027member\u0027 with no project_access rows, for whom the intended access-level check is skipped because getProjectAccess returns boolean true rather than a level object \u2014 can therefore make the server connect to any address reachable from it. The resulting HTTP status and status text are persisted as Import.errorMessage and returned by import.get to the same user, providing a scanning oracle for internal hosts, ports and paths; if an internal response parses as Umami CSV, its rows are ingested as events and become readable in the attacker\u0027s analytics views.",
"id": "GHSA-vmh2-9r6c-h7q4",
"modified": "2026-10-02T15:31:11Z",
"published": "2026-09-10T15:33:19Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/Openpanel-dev/openpanel/security/advisories/GHSA-cj2r-3x54-88h7"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-88892"
},
{
"type": "WEB",
"url": "https://github.com/Openpanel-dev/openpanel/commit/5faad3226df8fe03bc9434dfd255afb3fcea4c83"
},
{
"type": "WEB",
"url": "https://www.vulncheck.com/advisories/openpanel-ssrf-via-unguarded-importer-file-url-fetch"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N",
"type": "CVSS_V3"
},
{
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"type": "CVSS_V4"
}
]
}
GHSA-VMH7-9C7H-2PGG
Vulnerability from github – Published: 2026-04-27 21:31 – Updated: 2026-05-06 18:29A vulnerability was found in dh1011 auto-favicon up to f189116a9259950c2393f114dbcb94dde0ad864b. This issue affects the function generate_favicon_from_url of the file src/auto_favicon/server.py of the component MCP Tool. The manipulation of the argument image_url results in server-side request forgery. The attack may be performed from remote. The exploit has been made public and could be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The project was informed of the problem early through an issue report but has yet to receive a response.
{
"affected": [
{
"package": {
"ecosystem": "PyPI",
"name": "auto-favicon"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.0.1"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2026-7150"
],
"database_specific": {
"cwe_ids": [
"CWE-918"
],
"github_reviewed": true,
"github_reviewed_at": "2026-05-06T18:29:24Z",
"nvd_published_at": "2026-04-27T19:17:00Z",
"severity": "LOW"
},
"details": "A vulnerability was found in dh1011 auto-favicon up to f189116a9259950c2393f114dbcb94dde0ad864b. This issue affects the function generate_favicon_from_url of the file src/auto_favicon/server.py of the component MCP Tool. The manipulation of the argument image_url results in server-side request forgery. The attack may be performed from remote. The exploit has been made public and could be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The project was informed of the problem early through an issue report but has yet to receive a response.",
"id": "GHSA-vmh7-9c7h-2pgg",
"modified": "2026-05-06T18:29:24Z",
"published": "2026-04-27T21:31:02Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7150"
},
{
"type": "WEB",
"url": "https://github.com/dh1011/auto-favicon-mcp/issues/2"
},
{
"type": "PACKAGE",
"url": "https://github.com/dh1011/auto-favicon-mcp"
},
{
"type": "WEB",
"url": "https://vuldb.com/submit/802054"
},
{
"type": "WEB",
"url": "https://vuldb.com/vuln/359749"
},
{
"type": "WEB",
"url": "https://vuldb.com/vuln/359749/cti"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
"type": "CVSS_V3"
},
{
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"type": "CVSS_V4"
}
],
"summary": "auto-favicon has a Server-Side Request Forgery issue"
}
GHSA-VMXC-H2X2-JMF3
Vulnerability from github – Published: 2026-10-08 16:48 – Updated: 2026-10-08 16:48Summary
When an application using Pydantic AI opts a URL into local network access — either a FileUrl with force_download='allow-local', or web_fetch_tool(allow_local_urls=True) — the cloud-metadata blocklist could be bypassed by appending an IPv6 zone identifier to a metadata address (for example fd00:ec2::254%251). The host ignores the zone identifier on a destination that is not link-local and delivers the request to the metadata endpoint anyway, exposing cloud IAM short-term credentials.
This is an incomplete fix of GHSA-cqp8-fcvh-x7r3 / CVE-2026-46678 and GHSA-cg7w-rg45-pc59 / CVE-2026-48782, themselves follow-ups to CVE-2026-25580. The parent advisory's remediation guaranteed that cloud metadata endpoints are always blocked, even with local access allowed. That guarantee did not hold for zone-scoped spellings of the IPv6 metadata endpoints.
Details
The cloud-metadata guard compared IPv6 addresses against its blocklist by set membership. Python includes the zone identifier in IPv6Address equality and hashing, so a zone-scoped spelling of a blocked address did not match, while the network stack ignores the zone identifier for a destination that is not link-local. The private-range checks, and the IPv4 and transition-form metadata checks, were already unaffected, because they compare by network containment and by packed bytes respectively.
Only the IPv6 cloud metadata endpoints were reachable this way, so the issue requires an IPv6-enabled environment — for example AWS EC2 or EKS with IPv6, GCP IPv6-only instances, or Scaleway.
Who Is Affected
You are affected only if your application opts a URL that is, or could be, influenced by untrusted input into local network access, through either:
- a
FileUrl(ImageUrl,AudioUrl,VideoUrl,DocumentUrl) withforce_download='allow-local'; or web_fetch_tool(allow_local_urls=True), where the model chooses the URL.
Both are off by default.
You are not affected through the FileUrl path if you use any of the bundled integrations to ingest user input, because they do not propagate force_download from external data:
Agent.to_web/clai webVercelAIAdapterAGUIAdapter/Agent.to_ag_ui
web_fetch_tool is configured by your own application, so a client cannot turn on allow_local_urls.
Applications that only download from developer-controlled URLs are not affected.
Remediation
Upgrade to a patched version. The cloud-metadata and private-IP checks now drop an IPv6 zone identifier before evaluating the address, so every blocklist comparison is made on the address itself. A zone identifier is still carried on the connection, so legitimate link-local fetches under local network access continue to work.
Workaround for Unpatched Versions
Avoid opting into local network access — force_download='allow-local' or web_fetch_tool(allow_local_urls=True) — on any URL that could be influenced by untrusted input. If you must, reject URL hosts containing % before constructing the FileUrl or configuring the tool.
Credits
Reported by @euriconicacio.
{
"affected": [
{
"package": {
"ecosystem": "PyPI",
"name": "pydantic-ai"
},
"ranges": [
{
"events": [
{
"introduced": "1.56.0"
},
{
"fixed": "1.107.6"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "PyPI",
"name": "pydantic-ai"
},
"ranges": [
{
"events": [
{
"introduced": "2.0.0b1"
},
{
"fixed": "2.44.0"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "PyPI",
"name": "pydantic-ai-slim"
},
"ranges": [
{
"events": [
{
"introduced": "1.56.0"
},
{
"fixed": "1.107.6"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "PyPI",
"name": "pydantic-ai-slim"
},
"ranges": [
{
"events": [
{
"introduced": "2.0.0b1"
},
{
"fixed": "2.44.0"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2026-107289"
],
"database_specific": {
"cwe_ids": [
"CWE-1289",
"CWE-918"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-08T16:48:06Z",
"nvd_published_at": null,
"severity": "MODERATE"
},
"details": "### Summary\n\nWhen an application using Pydantic AI opts a URL into local network access \u2014 either a `FileUrl` with `force_download=\u0027allow-local\u0027`, or `web_fetch_tool(allow_local_urls=True)` \u2014 the cloud-metadata blocklist could be bypassed by appending an IPv6 zone identifier to a metadata address (for example `fd00:ec2::254%251`). The host ignores the zone identifier on a destination that is not link-local and delivers the request to the metadata endpoint anyway, exposing cloud IAM short-term credentials.\n\nThis is an incomplete fix of [GHSA-cqp8-fcvh-x7r3](https://github.com/pydantic/pydantic-ai/security/advisories/GHSA-cqp8-fcvh-x7r3) / [CVE-2026-46678](https://nvd.nist.gov/vuln/detail/CVE-2026-46678) and [GHSA-cg7w-rg45-pc59](https://github.com/pydantic/pydantic-ai/security/advisories/GHSA-cg7w-rg45-pc59) / [CVE-2026-48782](https://nvd.nist.gov/vuln/detail/CVE-2026-48782), themselves follow-ups to [CVE-2026-25580](https://nvd.nist.gov/vuln/detail/CVE-2026-25580). The parent advisory\u0027s remediation guaranteed that cloud metadata endpoints are always blocked, even with local access allowed. That guarantee did not hold for zone-scoped spellings of the IPv6 metadata endpoints.\n\n\n### Details\n\nThe cloud-metadata guard compared IPv6 addresses against its blocklist by set membership. Python includes the zone identifier in `IPv6Address` equality and hashing, so a zone-scoped spelling of a blocked address did not match, while the network stack ignores the zone identifier for a destination that is not link-local. The private-range checks, and the IPv4 and transition-form metadata checks, were already unaffected, because they compare by network containment and by packed bytes respectively.\n\nOnly the IPv6 cloud metadata endpoints were reachable this way, so the issue requires an IPv6-enabled environment \u2014 for example AWS EC2 or EKS with IPv6, GCP IPv6-only instances, or Scaleway.\n\n### Who Is Affected\n\nYou are affected **only if** your application opts a URL that is, or could be, influenced by untrusted input into local network access, through either:\n\n- a `FileUrl` (`ImageUrl`, `AudioUrl`, `VideoUrl`, `DocumentUrl`) with `force_download=\u0027allow-local\u0027`; or\n- `web_fetch_tool(allow_local_urls=True)`, where the model chooses the URL.\n\nBoth are off by default.\n\nYou are **not** affected through the `FileUrl` path if you use any of the bundled integrations to ingest user input, because they do not propagate `force_download` from external data:\n\n- `Agent.to_web` / `clai web`\n- `VercelAIAdapter`\n- `AGUIAdapter` / `Agent.to_ag_ui`\n\n`web_fetch_tool` is configured by your own application, so a client cannot turn on `allow_local_urls`.\n\nApplications that only download from developer-controlled URLs are not affected.\n\n### Remediation\n\nUpgrade to a patched version. The cloud-metadata and private-IP checks now drop an IPv6 zone identifier before evaluating the address, so every blocklist comparison is made on the address itself. A zone identifier is still carried on the connection, so legitimate link-local fetches under local network access continue to work.\n\n### Workaround for Unpatched Versions\n\nAvoid opting into local network access \u2014 `force_download=\u0027allow-local\u0027` or `web_fetch_tool(allow_local_urls=True)` \u2014 on any URL that could be influenced by untrusted input. If you must, reject URL hosts containing `%` before constructing the `FileUrl` or configuring the tool.\n\n### Credits\n\nReported by [@euriconicacio](https://github.com/euriconicacio).",
"id": "GHSA-vmxc-h2x2-jmf3",
"modified": "2026-10-08T16:48:07Z",
"published": "2026-10-08T16:48:06Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/pydantic/pydantic-ai/security/advisories/GHSA-vmxc-h2x2-jmf3"
},
{
"type": "WEB",
"url": "https://github.com/pydantic/pydantic-ai/pull/8401"
},
{
"type": "WEB",
"url": "https://github.com/pydantic/pydantic-ai/pull/8402"
},
{
"type": "WEB",
"url": "https://github.com/pydantic/pydantic-ai/commit/02157e1b87bd45d3f2e111ce07afdf89f9fb0e5b"
},
{
"type": "WEB",
"url": "https://github.com/pydantic/pydantic-ai/commit/4da70591460f51a8c4f128eaeef70a33340dbd55"
},
{
"type": "PACKAGE",
"url": "https://github.com/pydantic/pydantic-ai"
},
{
"type": "WEB",
"url": "https://github.com/pydantic/pydantic-ai/releases/tag/v1.107.6"
},
{
"type": "WEB",
"url": "https://github.com/pydantic/pydantic-ai/releases/tag/v2.44.0"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N",
"type": "CVSS_V3"
}
],
"summary": "Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv6 zone identifiers"
}
GHSA-VP3R-9RFC-JXQ2
Vulnerability from github – Published: 2026-09-09 03:30 – Updated: 2026-09-09 03:30Tanium addressed a server-side request forgery vulnerability in Enforce.
{
"affected": [],
"aliases": [
"CVE-2026-87084"
],
"database_specific": {
"cwe_ids": [
"CWE-918"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-09-09T03:17:27Z",
"severity": "HIGH"
},
"details": "Tanium addressed a server-side request forgery vulnerability in Enforce.",
"id": "GHSA-vp3r-9rfc-jxq2",
"modified": "2026-09-09T03:30:48Z",
"published": "2026-09-09T03:30:48Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-87084"
},
{
"type": "WEB",
"url": "https://security.tanium.com/TAN-2026-036"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-VP8W-WJ4M-3R7J
Vulnerability from github – Published: 2026-01-05 21:30 – Updated: 2026-01-05 23:15A Blind Server-Side Request Forgery (SSRF) vulnerability in evershop 2.1.0 and prior allows unauthenticated attackers to force the server to initiate an HTTP request via the "GET /images" API. The vulnerability occurs due to insufficient validation of the "src" query parameter, which permits arbitrary HTTP or HTTPS URIs, resulting in unexpected requests against internal and external networks.
{
"affected": [
{
"package": {
"ecosystem": "npm",
"name": "@evershop/evershop"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.1.0"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2025-67427"
],
"database_specific": {
"cwe_ids": [
"CWE-918"
],
"github_reviewed": true,
"github_reviewed_at": "2026-01-05T23:15:41Z",
"nvd_published_at": "2026-01-05T20:16:03Z",
"severity": "MODERATE"
},
"details": "A Blind Server-Side Request Forgery (SSRF) vulnerability in evershop 2.1.0 and prior allows unauthenticated attackers to force the server to initiate an HTTP request via the \"GET /images\" API. The vulnerability occurs due to insufficient validation of the \"src\" query parameter, which permits arbitrary HTTP or HTTPS URIs, resulting in unexpected requests against internal and external networks.",
"id": "GHSA-vp8w-wj4m-3r7j",
"modified": "2026-01-05T23:15:41Z",
"published": "2026-01-05T21:30:33Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-67427"
},
{
"type": "WEB",
"url": "https://github.com/dos-m0nk3y/CVE/tree/main/CVE-2025-67427"
},
{
"type": "PACKAGE",
"url": "https://github.com/evershopcommerce/evershop"
},
{
"type": "WEB",
"url": "https://pages.dos-m0nk3y.com/blog/EverShop%202.1.0%20-%20Unauthenticated%20DoS/#server-side-request-forgery-ssrf-cve-2025-67427"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P",
"type": "CVSS_V4"
}
],
"summary": "evershop allows unauthenticated attackers to force server to initiate HTTP request via \"GET /images\" API"
}
GHSA-VPFF-M9VH-PV4H
Vulnerability from github – Published: 2024-03-01 12:30 – Updated: 2024-03-10 03:30A vulnerability was found in Harrison Chase LangChain 0.1.9. It has been classified as critical. Affected is the function load_local in the library libs/community/langchain_community/retrievers/tfidf.py. The manipulation leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-255372.
{
"affected": [],
"aliases": [
"CVE-2024-2057"
],
"database_specific": {
"cwe_ids": [
"CWE-918"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-01T12:15:48Z",
"severity": "MODERATE"
},
"details": "A vulnerability was found in Harrison Chase LangChain 0.1.9. It has been classified as critical. Affected is the function load_local in the library libs/community/langchain_community/retrievers/tfidf.py. The manipulation leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-255372.",
"id": "GHSA-vpff-m9vh-pv4h",
"modified": "2024-03-10T03:30:45Z",
"published": "2024-03-01T12:30:53Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2057"
},
{
"type": "WEB",
"url": "https://github.com/langchain-ai/langchain/pull/18695"
},
{
"type": "WEB",
"url": "https://github.com/bayuncao/vul-cve-16"
},
{
"type": "WEB",
"url": "https://github.com/bayuncao/vul-cve-16/tree/main/PoC.pkl"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.255372"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.255372"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
"type": "CVSS_V3"
}
]
}
GHSA-VPJ2-MH86-XPMV
Vulnerability from github – Published: 2024-05-14 21:34 – Updated: 2024-05-14 21:34In WhatsUp Gold versions released before 2023.1.2 ,
a blind SSRF vulnerability exists in Whatsup Gold's FaviconController that allows an attacker to send arbitrary HTTP requests on behalf of the vulnerable server.
{
"affected": [],
"aliases": [
"CVE-2024-4561"
],
"database_specific": {
"cwe_ids": [
"CWE-918"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-14T21:15:13Z",
"severity": "MODERATE"
},
"details": "\nIn WhatsUp Gold versions released before 2023.1.2 , \n\na blind SSRF vulnerability exists in Whatsup Gold\u0027s FaviconController that allows an attacker to send arbitrary HTTP requests on behalf of the vulnerable server.\n\n",
"id": "GHSA-vpj2-mh86-xpmv",
"modified": "2024-05-14T21:34:44Z",
"published": "2024-05-14T21:34:44Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4561"
},
{
"type": "WEB",
"url": "https://community.progress.com/s/article/Announcing-WhatsUp-Gold-v2023-1-2"
},
{
"type": "WEB",
"url": "https://www.progress.com/network-monitoring"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-VPJF-Q5Q9-W837
Vulnerability from github – Published: 2026-01-28 06:30 – Updated: 2026-01-28 06:30The TableMaster for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.3.6. This is due to the plugin not restricting which URLs can be fetched when importing CSV data from a URL in the Data Table widget. This makes it possible for authenticated attackers, with Author-level access and above, to make web requests to arbitrary locations, including localhost and internal network services, and read sensitive files such as wp-config.php via the 'csv_url' parameter.
{
"affected": [],
"aliases": [
"CVE-2025-14610"
],
"database_specific": {
"cwe_ids": [
"CWE-918"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-01-28T06:15:48Z",
"severity": "HIGH"
},
"details": "The TableMaster for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.3.6. This is due to the plugin not restricting which URLs can be fetched when importing CSV data from a URL in the Data Table widget. This makes it possible for authenticated attackers, with Author-level access and above, to make web requests to arbitrary locations, including localhost and internal network services, and read sensitive files such as wp-config.php via the \u0027csv_url\u0027 parameter.",
"id": "GHSA-vpjf-q5q9-w837",
"modified": "2026-01-28T06:30:31Z",
"published": "2026-01-28T06:30:31Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-14610"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/tablemaster-for-elementor/tags/1.3.6/modules/data-table/widgets/data-table.php#L446"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/tablemaster-for-elementor/trunk/modules/data-table/widgets/data-table.php#L446"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/changeset?sfp_email=\u0026sfph_mail=\u0026reponame=\u0026old=3442158%40tablemaster-for-elementor\u0026new=3442158%40tablemaster-for-elementor\u0026sfp_email=\u0026sfph_mail="
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/ef07d6b0-ccdb-4b33-817f-6d4b3ad96243?source=cve"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-VPWG-HJ8F-G57P
Vulnerability from github – Published: 2026-07-14 18:32 – Updated: 2026-07-14 18:32Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
{
"affected": [],
"aliases": [
"CVE-2026-55051"
],
"database_specific": {
"cwe_ids": [
"CWE-918"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-07-14T18:18:17Z",
"severity": "MODERATE"
},
"details": "Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.",
"id": "GHSA-vpwg-hj8f-g57p",
"modified": "2026-07-14T18:32:34Z",
"published": "2026-07-14T18:32:34Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55051"
},
{
"type": "WEB",
"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55051"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-VQ23-39C6-74MP
Vulnerability from github – Published: 2022-09-03 00:00 – Updated: 2022-09-09 00:01Server-side Request Forgery (SSRF) vulnerability in PublicCMS before 4.0.202011.b via /publiccms/admin/ueditor when the action is catchimage.
{
"affected": [],
"aliases": [
"CVE-2021-27693"
],
"database_specific": {
"cwe_ids": [
"CWE-918"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2022-09-02T18:15:00Z",
"severity": "CRITICAL"
},
"details": "Server-side Request Forgery (SSRF) vulnerability in PublicCMS before 4.0.202011.b via /publiccms/admin/ueditor when the action is catchimage.",
"id": "GHSA-vq23-39c6-74mp",
"modified": "2022-09-09T00:01:00Z",
"published": "2022-09-03T00:00:18Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-27693"
},
{
"type": "WEB",
"url": "https://github.com/sanluan/PublicCMS/issues/51"
},
{
"type": "WEB",
"url": "https://github.com/sanluan/PublicCMS/commit/0f4c4872914b6a71305e121a7d9a19c07cde0338"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
]
}
No mitigation information available for this CWE.
CAPEC-664: Server Side Request Forgery
An adversary exploits improper input validation by submitting maliciously crafted input to a target application running on a server, with the goal of forcing the server to make a request either to itself, to web services running in the server’s internal network, or to external third parties. If successful, the adversary’s request will be made with the server’s privilege level, bypassing its authentication controls. This ultimately allows the adversary to access sensitive data, execute commands on the server’s network, and make external requests with the stolen identity of the server. Server Side Request Forgery attacks differ from Cross Site Request Forgery attacks in that they target the server itself, whereas CSRF attacks exploit an insecure user authentication mechanism to perform unauthorized actions on the user's behalf.