Server-Side Request Forgery in Gophish by Gophish Team
CVE-2026-107273
Key Information:
Badges
What is CVE-2026-107273?
Gophish versions 0.11.0 to 0.12.1 are prone to a server-side request forgery vulnerability that can be exploited by authenticated low-privileged users. Through the endpoint POST /api/import/site, attackers are able to submit internal URLs that are not blocked by the default dialer deny list. This vulnerability may allow attackers to access loopback and private hosts, enabling them to read service responses and probe internal hosts and ports via the error messages returned.
Affected Version(s)
gophish 0.11.0 <= 0.12.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
