Mifi · Lossless-Cut · CVE-2026-19352
**Name of the Vulnerable Software and Affected Versions**
mifi lossless-cut versions prior to 3.69.1
**Description**
A server-side request forgery issue exists within the Built-in HTTP API Service component, specifically in the `src/main/httpServer.ts` file. This flaw allows an attacker with local network access to execute a manipulation that triggers the server to make unauthorized requests. The issue is associated with NTLM behavior and is accessible via an experimental CLI flag. Exploitation is characterized by high complexity and is considered difficult.
**Recommendations**
Apply patch 260802348955231442c4bae6c2d9d8ede947af0a to resolve the issue.
As a temporary mitigation, avoid using the experimental CLI flag that enables the Built-in HTTP API Service.