PT-2026-22627 · Casaos+1 · Casaos+1

Published

2026-03-02

·

Updated

2026-03-06

·

CVE-2025-64427

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
Name of the Vulnerable Software and Affected Versions ZimaOS versions prior to 1.5.1
Description ZimaOS, a fork of CasaOS, is susceptible to a flaw stemming from inadequate validation or restriction of target URLs. An authenticated local user can construct requests that target internal IP addresses, such as 127.0.0.1, localhost, or private network ranges. This enables interaction with internal HTTP/HTTPS services not intended for external or local user access.
Recommendations Update ZimaOS to version 1.5.1 or later. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Information Disclosure

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-64427
GHSA-M8HJ-7XG5-P375

Affected Products

Casaos
Zimaos