PT-2026-70150 · Pinry · Pinry
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Pinry versions prior to 2.1.14
Description
A server-side request forgery (SSRF) issue exists in the pin-from-URL feature. This occurs because the application passes a user-supplied URL directly to the
requests.get() function without validating the host or IP address. Since ALLOW NEW REGISTRATIONS is set to true by default, unauthenticated remote attackers can trigger this behavior to force the server to send HTTP requests to arbitrary internal or external hosts, potentially accessing internal services or cloud metadata endpoints.Recommendations
Update Pinry to version 2.1.14 or later.
Set the
ALLOW NEW REGISTRATIONS variable to false to prevent anonymous triggering of the feature.Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pinry