VYPR

Moviepilot

by Jxxghp

CVEs (1)

  • CVE-2026-10107HigMay 29, 2026
    risk 0.50cvss 7.7epss

    MoviePilot v2 contains a server-side request forgery vulnerability in the image proxy endpoint that allows authenticated attackers to request arbitrary URLs by supplying a resource_token cookie and a URL whose domain matches the assembled allowlist. Attackers can bypass internal…