SSRF Vulnerability in Ghostfolio Wealth Management Software
CVE-2026-28680

9.3CRITICAL

Key Information:

Vendor

Ghostfolio

Vendor
CVE Published:
6 March 2026

What is CVE-2026-28680?

Ghostfolio, a popular open-source wealth management software, has a vulnerability in its manual asset import feature that could be exploited by attackers. This vulnerability enables a full-read Server-Side Request Forgery (SSRF) attack, allowing unauthorized access to sensitive cloud metadata and potentially internal network services. Users are strongly encouraged to upgrade to version 2.245.0 or later to mitigate this risk.

Affected Version(s)

ghostfolio < 2.245.0

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.