Server-Side Request Forgery Vulnerability in Pentestify by CCYL
CVE-2026-59231
5.3MEDIUM
What is CVE-2026-59231?
The Pentestify PDF export component prior to version 1.1.0 is susceptible to Server-Side Request Forgery (SSRF) due to unvalidated URLs. Authenticated users can exploit this flaw to send arbitrary HTTP GET requests from the server to potentially malicious destinations. This occurs when untrusted URLs, which can be stored in the finding images field or the report client_logo field, are fetched by a server-side headless browser during report rendering. It is crucial for users to upgrade to version 1.1.1 or later to mitigate this risk.
Affected Version(s)
Pentestify 0 < 1.1.0
References
CVSS V4
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Marcos Turrión García (marcosturriongarcia2005)
Xoán M. Otero Jorge
Secur0 CNA
Mario Álvarez Fernández (maalfer)
Cristian Fernandez Cornejo
