Critical Server-Side Request Forgery Vulnerability (CVE-2026-19927) Disclosed in OpenBoxes
A critical server-side request forgery (SSRF) vulnerability, tracked as CVE-2026-19927, has been identified in OpenBoxes versions up to 0.9.7. The flaw, located in the Product Upload Endpoint's `Upload` function, allows remote attackers to manipulate the `params.url` argument, leading to unauthorized requests on behalf of the system. An exploit has been made public, and users are advised to upgrade to version 0.9.8-hotfix1 or 0.9.8 to resolve the issue.
Want more?
Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.
Open NewsSnap.ai