Server-Side Request Forgery in Kasuganosoras Pigeon 1.0.177
CVE-2025-1447
What is CVE-2025-1447?
A significant security issue has been identified in the Pigeon product by Kasuganosoras, specifically in version 1.0.177, where the manipulation of the 'url' parameter in the /pigeon/imgproxy/index.php file can lead to remote server-side request forgery. This vulnerability allows attackers to exploit the issue remotely, causing unwanted interactions between the server and other internal resources. Users are strongly advised to upgrade to version 1.0.181 to mitigate this risk. The necessary patch can be found in commit 84cea5fe73141689da2e7ec8676d47435bd6423e.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Pigeon 1.0.177
References
CVSS V4
Timeline
Vulnerability published
