PT-2026-95971 · Mealie · Mealie
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Mealie versions prior to 3.26.0
Description
A weakness in the Recipe Action Trigger component allows for remote server-side request forgery (SSRF), a condition where an attacker can induce the server to make requests to an unintended location. The issue exists within the
payload.model dump() function located in the mealie/routes/households/controller group recipe actions.py file. This occurs when the url argument is manipulated.Recommendations
Upgrade to version 3.26.0.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mealie