PT-2026-56486 · Repomix · Repomix

·

CVE-2026-59702

·

Published

2026-07-08

·

Updated

2026-07-10

CVSS v3.1

9.3

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions repomix (affected versions not specified)
Description A server-side request forgery (SSRF) issue exists in the 'POST /api/pack' endpoint. This occurs because the endpoint does not properly validate http://, https://, and file:// URLs before they are passed to the git clone function. Consequently, unauthenticated attackers can initiate arbitrary outbound requests to access private network addresses, GCP metadata services, or local filesystem paths.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. Avoid using the 'POST /api/pack' endpoint until the issue is resolved.

Exploit

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-59702

Affected Products

Repomix