VYPR

Server

by Sync In

Source repositories

CVEs (1)

  • CVE-2026-47684higJun 5, 2026
    risk 0.38cvss epss

    Summary: The private IP blocklist regex used in the URL download feature does not match IPv4-mapped IPv6 addresses (e.g. ::ffff:127.0.0.1), allowing SSRF protection to be bypassed on dual-stack systems. Affected components backend/src/applications/files/services/files-manager.s…