PT-2026-56486 · Repomix · Repomix
CVSS v3.1
9.3
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
repomix (affected versions not specified)
Description
A server-side request forgery (SSRF) issue exists in the 'POST /api/pack' endpoint. This occurs because the endpoint does not properly validate
http://, https://, and file:// URLs before they are passed to the git clone function. Consequently, unauthenticated attackers can initiate arbitrary outbound requests to access private network addresses, GCP metadata services, or local filesystem paths.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Avoid using the 'POST /api/pack' endpoint until the issue is resolved.
Exploit
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Repomix