GHSA-gmxh-hjfv-qc2wHighCVSS 8.1
Koillection has an authenticated Server-Side Request Forgery issue
🔗 CVE IDs covered (1)
📋 Description
An authenticated Server-Side Request Forgery (SSRF) in the custom scraper subsystem component of Benjamin Jonard Koillection v1.8.0 allows attackers to scan internal resources via supplying a crafted URL.
🎯 Affected products1
- composer/koillection/koillection:< 1.8.4
🔗 References (6)
- https://nvd.nist.gov/vuln/detail/CVE-2026-50888
- https://gist.github.com/pyuysig/d60273c1c346257ceddbf8da7134bae7
- https://github.com/benjaminjonard/koillection/pull/1599
- https://github.com/benjaminjonard/koillection/commit/4d445e21c631c26070f19fe8ec086a2939767ae0
- https://github.com/benjaminjonard/koillection/releases/tag/1.8.4
- https://github.com/advisories/GHSA-gmxh-hjfv-qc2w