Unrated severityNVD Advisory· Published Jul 8, 2026· Updated Jul 20, 2026
repomix - Server-Side Request Forgery via Unvalidated Repository URLs in POST /api/pack
CVE-2026-59702
Description
repomix contains a server-side request forgery vulnerability in the POST /api/pack endpoint that allows unauthenticated attackers to make arbitrary outbound requests. The endpoint fails to properly validate http://, https://, and file:// URLs before passing them to git clone, enabling attackers to access private network addresses, GCP metadata services, or local filesystem paths.
Affected products
1Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.