PT-2025-15123 · Lnbits+1 · Lnbits+1

Published

2025-04-06

·

Updated

2025-04-11

·

CVE-2025-32013

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions LNbits (affected versions not specified)
Description A Server-Side Request Forgery (SSRF) issue has been found in LNbits' LNURL authentication handling functionality. This occurs because the application does not properly validate the callback URL parameter when processing LNURL authentication requests, allowing attackers to specify internal network addresses and access internal resources. The application makes an HTTP request to the specified URL using the httpx library with redirect following enabled.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-32013
GHSA-QP8J-P87F-C8CC
PYSEC-2025-16

Affected Products

Lnbits
Httpx