PT-2026-69293 · Mifi · Lossless-Cut

·

CVE-2026-19352

·

Published

2026-08-09

·

Updated

2026-08-09

CVSS v3.1

3.1

Low

VectorAV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions mifi lossless-cut versions prior to 3.69.1
Description A server-side request forgery issue exists within the Built-in HTTP API Service component, specifically in the src/main/httpServer.ts file. This flaw allows an attacker with local network access to execute a manipulation that triggers the server to make unauthorized requests. The issue is associated with NTLM behavior and is accessible via an experimental CLI flag. Exploitation is characterized by high complexity and is considered difficult.
Recommendations Apply patch 260802348955231442c4bae6c2d9d8ede947af0a to resolve the issue. As a temporary mitigation, avoid using the experimental CLI flag that enables the Built-in HTTP API Service.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19352

Affected Products

Lossless-Cut