Server-side Request Forgery Vulnerability in Shopware Platform
CVE-2026-48013
4.1MEDIUM
What is CVE-2026-48013?
In Shopware, a server-side request forgery (SSRF) vulnerability exists that allows authenticated admin users to perform HTTP HEAD requests to internal IP addresses via the /api/_action/media/external-link endpoint. The vulnerability arises because the linkURL flow bypasses essential validation on target IP addresses, only checking for basic URL formatting, thus exposing internal network services and cloud metadata endpoints to potential exploitation. This issue is addressed in the versions 6.6.10.18 and 6.7.10.1.
Affected Version(s)
platform < 6.6.10.18 < 6.6.10.18
platform >= 6.7.0.0, < 6.7.10.1 < 6.7.0.0, 6.7.10.1
shopware < 6.6.10.18 < 6.6.10.18
