CVE-2026-72597 UNKNOWN

CVE-2026-72597

Published: 2026-08-11

Description

A server-side request forgery vulnerability in Friendica through the 2026.08-dev branch allows authenticated users with a free self-registered account to probe internal network services via the link-preview endpoint. The endpoint fetches any user-supplied URL without applying an internal IP deny list. An attacker can use this to scan the internal network or access cloud metadata services.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…