High severity8.1NVD Advisory· Published Jun 15, 2026· Updated Jun 16, 2026
CVE-2026-50888
CVE-2026-50888
Description
An authenticated Server-Side Request Forgery (SSRF) in the custom scraper subsystem component of Benjamin Jonard Koillection v1.8.0 allows attackers to scan internal resources via supplying a crafted URL.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
koillection/koillectionPackagist | < 1.8.4 | 1.8.4 |
Affected products
3- Range: = 1.8.0
- Range: =1.8.0
Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-gmxh-hjfv-qc2wghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-50888ghsaADVISORY
- gist.github.com/pyuysig/d60273c1c346257ceddbf8da7134bae7nvdWEB
- github.com/benjaminjonard/koillection/commit/4d445e21c631c26070f19fe8ec086a2939767ae0ghsaWEB
- github.com/benjaminjonard/koillection/pull/1599ghsaWEB
- github.com/benjaminjonard/koillection/releases/tag/1.8.4ghsaWEB
News mentions
0No linked articles in our index yet.