VYPR
High severity7.7OSV Advisory· Published Aug 10, 2026· Updated Aug 28, 2026

CVE-2026-72591

CVE-2026-72591

Description

A server-side request forgery (SSRF) vulnerability in gabehf/Koito through v0.3.2 allows an authenticated user to make the server perform HTTP requests to arbitrary internal or external hosts by supplying a crafted image_url value in the PATCH /apis/web/v1/album/{id}/image endpoint.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Gabehf/Koitollm-fuzzy2 versions
    <=0.3.2+ 1 more
    • (no CPE)range: <=0.3.2
    • (no CPE)range: v0.3.1, v0.3.0, v0.2.1, …

Patches

Vulnerability mechanics

News mentions

0

No linked articles in our index yet.