Server-Side Request Forgery Vulnerability in Pentestify by CCYL
CVE-2026-59231

5.3MEDIUM

Key Information:

Vendor

Ccyl13

Vendor
CVE Published:
31 July 2026

What is CVE-2026-59231?

The Pentestify PDF export component prior to version 1.1.0 is susceptible to Server-Side Request Forgery (SSRF) due to unvalidated URLs. Authenticated users can exploit this flaw to send arbitrary HTTP GET requests from the server to potentially malicious destinations. This occurs when untrusted URLs, which can be stored in the finding images field or the report client_logo field, are fetched by a server-side headless browser during report rendering. It is crucial for users to upgrade to version 1.1.1 or later to mitigate this risk.

Affected Version(s)

Pentestify 0 < 1.1.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Marcos Turrión García (marcosturriongarcia2005)
Xoán M. Otero Jorge
Secur0 CNA
Mario Álvarez Fernández (maalfer)
Cristian Fernandez Cornejo
.