PT-2026-66769 · Maalfer · Pentestify

·

CVE-2026-59231

·

Published

2026-07-31

·

Updated

2026-07-31

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions maalfer Pentestify versions prior to 1.1.0
Description An issue in the PDF export component allows authenticated users to trigger outbound HTTP GET requests from the server to arbitrary destinations. This occurs because the server-side headless browser fetches unvalidated URLs stored in the finding images field or the report client logo field during report rendering. Server-Side Request Forgery (SSRF) is a flaw where an attacker can force a server to make requests to an unintended location.
Recommendations Update maalfer Pentestify to version 1.1.0 or later. Restrict the use of the finding images and report client logo fields to trusted sources until the update is applied.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-59231

Affected Products

Pentestify