PT-2026-28504 · Lychee · Lychee

Morimori-Dev

·

Published

2026-03-26

·

Updated

2026-03-26

·

CVE-2026-33644

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Lychee versions prior to 7.5.2
Description Lychee is a free, open-source photo-management tool. Prior to version 7.5.2, the Server-Side Request Forgery (SSRF) protection in PhotoUrlRule.php could be bypassed using DNS rebinding. The IP validation check (lines 86-89) only activates when the hostname is an IP address. When a domain name is used, filter var($host, FILTER VALIDATE IP) returns false, skipping the entire check. This allows for potential unauthorized access or actions through the vulnerable application.
Recommendations Update to Lychee version 7.5.2 or later.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-33644
GHSA-5245-4P8C-JWFF

Affected Products

Lychee