PT-2026-8023 · Unknown · Tandoor Recipes

Drkim-Dev

·

Publicado

2026-02-13

·

Atualizado

2026-02-18

·

CVE-2026-25991

CVSS v3.1

7.7

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Tandoor Recipes versions prior to 2.5.1
Description Tandoor Recipes is an application used for recipe management, meal planning, and shopping list creation. A Blind Server-Side Request Forgery (SSRF) exists in the Cookmate recipe import feature prior to version 2.5.1. The application does not properly validate the destination URL after HTTP redirects, enabling authenticated users to make the server connect to arbitrary internal or external resources. The issue resides in the cookbook/integration/cookmate.py file, within the Cookmate integration class. This can be used to scan internal network ports, access cloud instance metadata, or reveal the server’s real IP address. The vulnerable function is Cookmate.
Recommendations Update Tandoor Recipes to version 2.5.1 or later.

Exploit

Correção

SSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-25991
GHSA-J6XG-85MH-QQF7

Produtos afetados

Tandoor Recipes