PT-2026-71457 · Unknown · Serendipity

·

CVE-2026-73629

·

Published

2026-08-13

·

Updated

2026-08-13

CVSS v3.1

8.5

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Serendipity versions prior to 2.6.0
Description An issue exists in the serendipity url allowed() filter that fails to block hex-encoded IPv4 addresses, IPv6 literals, and link-local ranges. Authenticated users with adminImagesAdd permission can bypass this filter using alternate address formats to perform a server-side request forgery, allowing them to request internal services and retrieve response bodies through the public uploads directory.
Recommendations Update to version 2.6.0 or later.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73629
GHSA-2M48-GJJ5-5X86

Affected Products

Serendipity