repomix contains a server-side request forgery vulnerability in the POST /api/pack endpoint that allows unauthenticated attackers to make arbitrary outbound requests. The endpoint fails to properly validate http://, https://, and file:// URLs before passing them to git clone, enabling attackers to access private network addresses, GCP metadata services, or local filesystem paths.
CVE-2026-59702
Score 9.3 from GitHub Security Advisory (severity: CRITICAL) published 2026-07-08. the CNA's CVSS baseline 9.3; sources differ by 0.0.
- High severity, but no confirmed exploitation yet
No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.
- CVSS v3
- 9.3
- EG Score
- 9.3(medium)
- EG Risk
- 73(Attend)EG Risk 73/100SSVC: Attend
EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).
How it’s computedSeverity93% × 45%Exploitation40% × 40%Automatability100% × 15%Action: Remediate soon — notable exploitation risk. - EPSS PROB
- 0%
- EPSS %ILE
- 37%
- KEV
- Not listed
Published
July 8, 2026
Last Modified
August 14, 2026
Advisory Details (4)
Auto-updated Aug 23, 2026repomix - Server-Side Request Forgery via Unvalidated Repository URLs in POST /api/pack | Advisories | VulnCheck
https://www.vulncheck.com/advisories/repomix-server-side-request-forgery-via-unvalidated-repository-urls-in-post-api-packcommit c748b524f412 (CrazyForks/repomix)
Fix landed in CrazyForks/repomix commit c748b524f412 — awaiting tagged release
https://github.com/CrazyForks/repomix/commit/c748b524f41225e7fc6f89ad0084520901a453cfGitHub - yamadashy/repomix: 📦 Repomix is a powerful tool that packs your entire repository into a single, AI-friendly file. Perfect for when you need to feed your codebase to Large Language Models (LLMs) or other AI tools like Claude, ChatGPT, DeepSeek, Perplexity, Gemini, Gemma, Llama, Grok, and more. · GitHub
https://github.com/yamadashy/repomixWebsite server allows SSRF via arbitrary http:// URLs to internal network endpoints · Issue #1703 · yamadashy/repomix · GitHub
https://github.com/yamadashy/repomix/issues/1703Vendor Advisories for CVE-2026-59702(1)
These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.
Weakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Data Freshness Timeline
(refreshed 29× in last 7d / 210× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
Showing the most recent 100 of 334 total refreshes for this CVE.
- 2026-08-30 07:37 UTCEG score recompute
- 2026-08-30 07:37 UTCGHSA enrichment
- 2026-08-30 01:22 UTCEPSS rescore
- 2026-08-28 21:42 UTCEPSS rescore
- 2026-08-28 02:43 UTCGHSA enrichment
- 2026-08-27 21:51 UTCEG score recompute
- 2026-08-27 21:51 UTCGHSA enrichment
- 2026-08-27 14:25 UTCEPSS rescore
- 2026-08-27 01:31 UTCEG score recompute
- 2026-08-27 01:31 UTCGHSA enrichment
- 2026-08-26 14:46 UTCEPSS rescore
- 2026-08-26 12:56 UTCGHSA enrichment
- 2026-08-26 08:25 UTCGHSA enrichment
- 2026-08-25 14:48 UTCEG score recompute
- 2026-08-25 14:48 UTCGHSA enrichment
- 2026-08-25 13:49 UTCEPSS rescore
- 2026-08-25 10:13 UTCGHSA enrichment
- 2026-08-25 04:19 UTCGHSA enrichment
- 2026-08-25 00:27 UTCGHSA enrichment
- 2026-08-24 20:34 UTCEG score recompute
- 2026-08-24 20:34 UTCGHSA enrichment
- 2026-08-24 13:35 UTCGHSA enrichment
- 2026-08-24 09:42 UTCEG score recompute
- 2026-08-24 09:42 UTCGHSA enrichment
- 2026-08-24 04:04 UTCGHSA enrichment
Show 75 moreShow fewer
- 2026-08-23 23:05 UTCGHSA enrichment
- 2026-08-23 18:45 UTCGHSA enrichment
- 2026-08-23 14:53 UTCGHSA enrichment
- 2026-08-23 11:00 UTCGHSA enrichment
- 2026-08-23 07:08 UTCGHSA enrichment
- 2026-08-23 03:15 UTCEG score recompute
- 2026-08-23 03:15 UTCGHSA enrichment
- 2026-08-23 00:19 UTCEPSS rescore
- 2026-08-22 23:15 UTCGHSA enrichment
- 2026-08-22 19:21 UTCGHSA enrichment
- 2026-08-22 15:28 UTCGHSA enrichment
- 2026-08-22 11:35 UTCGHSA enrichment
- 2026-08-22 07:42 UTCGHSA enrichment
- 2026-08-22 03:49 UTCEG score recompute
- 2026-08-22 03:49 UTCGHSA enrichment
- 2026-08-21 23:49 UTCEPSS rescore
- 2026-08-21 23:32 UTCGHSA enrichment
- 2026-08-21 19:39 UTCGHSA enrichment
- 2026-08-21 15:46 UTCGHSA enrichment
- 2026-08-21 11:50 UTCGHSA enrichment
- 2026-08-21 07:52 UTCGHSA enrichment
- 2026-08-21 03:59 UTCGHSA enrichment
- 2026-08-20 23:23 UTCEG score recompute
- 2026-08-20 23:23 UTCGHSA enrichment
- 2026-08-20 22:55 UTCEPSS rescore
- 2026-08-20 19:31 UTCGHSA enrichment
- 2026-08-20 15:38 UTCGHSA enrichment
- 2026-08-20 09:45 UTCGHSA enrichment
- 2026-08-20 05:53 UTCGHSA enrichment
- 2026-08-20 02:00 UTCEG score recompute
- 2026-08-20 02:00 UTCGHSA enrichment
- 2026-08-19 17:04 UTCEPSS rescore
- 2026-08-19 16:28 UTCGHSA enrichment
- 2026-08-19 12:29 UTCGHSA enrichment
- 2026-08-19 08:36 UTCGHSA enrichment
- 2026-08-19 04:43 UTCGHSA enrichment
- 2026-08-19 00:47 UTCGHSA enrichment
- 2026-08-18 20:45 UTCEG score recompute
- 2026-08-18 20:45 UTCGHSA enrichment
- 2026-08-18 13:48 UTCEPSS rescore
- 2026-08-18 11:34 UTCGHSA enrichment
- 2026-08-18 07:16 UTCGHSA enrichment
- 2026-08-18 02:59 UTCGHSA enrichment
- 2026-08-17 22:29 UTCGHSA enrichment
- 2026-08-17 15:15 UTCEG score recompute
- 2026-08-17 15:15 UTCGHSA enrichment
- 2026-08-17 13:47 UTCEPSS rescore
- 2026-08-17 11:22 UTCGHSA enrichment
- 2026-08-17 07:29 UTCGHSA enrichment
- 2026-08-17 03:37 UTCGHSA enrichment
- 2026-08-16 23:44 UTCGHSA enrichment
- 2026-08-16 19:51 UTCGHSA enrichment
- 2026-08-16 15:58 UTCEG score recompute
- 2026-08-16 15:58 UTCGHSA enrichment
- 2026-08-16 14:56 UTCEPSS rescore
- 2026-08-16 12:05 UTCGHSA enrichment
- 2026-08-16 08:13 UTCGHSA enrichment
- 2026-08-16 04:21 UTCEG score recompute
- 2026-08-16 04:21 UTCGHSA enrichment
- 2026-08-16 02:14 UTCEPSS rescore
- 2026-08-16 00:29 UTCGHSA enrichment
- 2026-08-15 20:36 UTCGHSA enrichment
- 2026-08-15 16:43 UTCGHSA enrichment
- 2026-08-15 12:50 UTCGHSA enrichment
- 2026-08-15 08:51 UTCGHSA enrichment
- 2026-08-15 04:58 UTCEG score recompute
- 2026-08-15 04:58 UTCGHSA enrichment
- 2026-08-15 01:30 UTCEPSS rescore
- 2026-08-15 01:05 UTCGHSA enrichment
- 2026-08-14 21:12 UTCGHSA enrichment
- 2026-08-14 17:20 UTCGHSA enrichment
- 2026-08-14 14:37 UTCGHSA enrichment
- 2026-08-14 10:45 UTCGHSA enrichment
- 2026-08-14 06:52 UTCGHSA enrichment
- 2026-08-14 03:00 UTCGHSA enrichment
Related CVEs(same CWE)
Same CWE
10 shownCWE-918
- CVE-2016-10927EG 10.0CRITICAL
- CVE-2016-10926EG 10.0CRITICAL
- CVE-2018-10511EG 10.0CRITICAL
- CVE-2018-1000124EG 10.0CRITICAL
- CVE-2017-11291EG 10.0EPSS p91CRITICAL
- CVE-2017-12905EG 10.0CRITICAL
- CVE-2017-8794EG 10.0CRITICAL
- CVE-2017-13667EG 9.9CRITICAL
- CVE-2017-17674EG 9.8CRITICAL
- CVE-2013-4864EG 9.8EPSS p93CRITICAL
Frequently asked(5)
What is CVE-2026-59702?
When was CVE-2026-59702 disclosed?
Is CVE-2026-59702 actively exploited?
What is the CVSS score of CVE-2026-59702?
How do I remediate CVE-2026-59702?
Dependency Blast Radius
Explore the affected products and dependency analysis for CVE-2026-59702
Is Your Infrastructure Affected by CVE-2026-59702?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.