PT-2026-70150 · Pinry · Pinry

·

CVE-2026-72606

·

Published

2026-08-11

·

Updated

2026-08-11

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Pinry versions prior to 2.1.14
Description A server-side request forgery (SSRF) issue exists in the pin-from-URL feature. This occurs because the application passes a user-supplied URL directly to the requests.get() function without validating the host or IP address. Since ALLOW NEW REGISTRATIONS is set to true by default, unauthenticated remote attackers can trigger this behavior to force the server to send HTTP requests to arbitrary internal or external hosts, potentially accessing internal services or cloud metadata endpoints.
Recommendations Update Pinry to version 2.1.14 or later. Set the ALLOW NEW REGISTRATIONS variable to false to prevent anonymous triggering of the feature.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-72606

Affected Products

Pinry