GHSA-gmxh-hjfv-qc2wHighCVSS 8.1

Koillection has an authenticated Server-Side Request Forgery issue

Published
June 15, 2026
Last Modified
August 27, 2026

🔗 CVE IDs covered (1)

📋 Description

An authenticated Server-Side Request Forgery (SSRF) in the custom scraper subsystem component of Benjamin Jonard Koillection v1.8.0 allows attackers to scan internal resources via supplying a crafted URL.

🎯 Affected products1

  • composer/koillection/koillection:< 1.8.4

🔗 References (6)