Server-Side Request Forgery in FlaskBB Forum Software by Flask
CVE-2026-46556
6.5MEDIUM
What is CVE-2026-46556?
FlaskBB, a popular forum software built on the Flask micro framework, has a vulnerability that allows authenticated users to exploit the get_image_info() function to perform Server-Side Request Forgery. This flaw enables attackers to send HTTP requests to internal endpoints, potentially accessing sensitive internal services, including cloud metadata. The issue is classified as a blind SSRF due to its capacity for internal port scanning and triggering internal APIs. Users are advised to upgrade to version 2.2.1 or later to mitigate this risk.
Affected Version(s)
flaskbb < 2.2.1
