PT-2026-24890 · Zyddnys · Manga-Image-Translator

Zast.Ai

·

Publicado

2026-03-11

·

Atualizado

2026-03-12

·

CVE-2026-3961

CVSS v2.0

6.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions zyddnys manga-image-translator versions through beta-0.3
Description A server-side request forgery condition exists in zyddnys manga-image-translator. The issue is located in the to pil image function within the request extraction.py file of the Translate Endpoints component. This manipulation can lead to server-side request forgery, and the attack can be initiated remotely. The exploit has been publicly disclosed. The project maintainers were notified of the issue but have not yet responded.
Recommendations Versions prior to beta-0.3 should be used. As a temporary workaround, consider restricting access to the to pil image() function until a patch is available.

Exploit

Correção

SSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-3961

Produtos afetados

Manga-Image-Translator