Medium severity4.3NVD Advisory· Published Oct 7, 2026· Updated Oct 7, 2026
CVE-2026-107273
CVE-2026-107273
Description
Gophish 0.11.0 through 0.12.1 contains a server-side request forgery vulnerability that allows authenticated low-privileged users to reach loopback and private hosts via POST /api/import/site. Attackers can submit internal URLs, which the default dialer deny list does not block, to read service responses and enumerate internal hosts and ports through error messages.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
4- blog.ostorlab.co/gophish-0121-manual-review-agentic-deep-scan.htmlnvd
- github.com/gophish/gophish/blob/b1648f0759c6d57ac989157c55d8b47c40254fe6/controllers/api/import.gonvd
- github.com/gophish/gophish/blob/b1648f0759c6d57ac989157c55d8b47c40254fe6/dialer/dialer.gonvd
- www.vulncheck.com/advisories/gophish-0.11.0-through-0.12.1-ssrf-via-post-api-import-sitenvd
News mentions
0No linked articles in our index yet.