PT-2026-28504 · Lychee · Lychee
Morimori-Dev
·
Published
2026-03-26
·
Updated
2026-03-26
·
CVE-2026-33644
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Lychee versions prior to 7.5.2
Description
Lychee is a free, open-source photo-management tool. Prior to version 7.5.2, the Server-Side Request Forgery (SSRF) protection in
PhotoUrlRule.php could be bypassed using DNS rebinding. The IP validation check (lines 86-89) only activates when the hostname is an IP address. When a domain name is used, filter var($host, FILTER VALIDATE IP) returns false, skipping the entire check. This allows for potential unauthorized access or actions through the vulnerable application.Recommendations
Update to Lychee version 7.5.2 or later.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lychee