Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hggv-jxwf-w664

Опубликовано: 25 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.3
CVSS3: 8.5

Описание

NewsBlur before version 14.5.0 contains a server-side request forgery vulnerability in the add_url endpoint that allows authenticated users to make arbitrary server requests to internal networks by failing to filter private IP addresses. Attackers can exploit this to access localhost services and cloud metadata endpoints, enabling internal network scanning and sensitive data exfiltration.

NewsBlur before version 14.5.0 contains a server-side request forgery vulnerability in the add_url endpoint that allows authenticated users to make arbitrary server requests to internal networks by failing to filter private IP addresses. Attackers can exploit this to access localhost services and cloud metadata endpoints, enabling internal network scanning and sensitive data exfiltration.

EPSS

Процентиль: 28%
0.00351
Низкий

6.3 Medium

CVSS4

8.5 High

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 8.5
nvd
2 месяца назад

NewsBlur before version 14.5.0 contains a server-side request forgery vulnerability in the add_url endpoint that allows authenticated users to make arbitrary server requests to internal networks by failing to filter private IP addresses. Attackers can exploit this to access localhost services and cloud metadata endpoints, enabling internal network scanning and sensitive data exfiltration.

EPSS

Процентиль: 28%
0.00351
Низкий

6.3 Medium

CVSS4

8.5 High

CVSS3

Дефекты

CWE-918