Server-Side Request Forgery in Friendica Affects Authenticated Users
CVE-2026-72597
6.5MEDIUM
What is CVE-2026-72597?
A server-side request forgery vulnerability exists in Friendica through the 2026.08-dev branch. This flaw permits authenticated users with self-registered accounts to exploit the link-preview endpoint, which indiscriminately fetches user-supplied URLs. Due to the lack of an internal IP deny list, this vulnerability enables attackers to probe internal network services or gain unauthorized access to cloud metadata services. Protecting against such vulnerabilities is crucial to safeguard network integrity.
Affected Version(s)
Friendica 0 <= 2026.08-dev
