PT-2026-35517 · Unknown · Auto-Favicon
Mida
·
Published
2026-04-27
·
Updated
2026-04-28
·
CVE-2026-7150
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
dh1011 auto-favicon versions up to f189116a9259950c2393f114dbcb94dde0ad864b
Description
An issue in the MCP Tool component allows remote attackers to perform server-side request forgery (SSRF), which is a flaw where a server is tricked into making unauthorized requests to internal or external resources. This occurs through the manipulation of the
image url argument within the generate favicon from url() function located in the 'src/auto favicon/server.py' file.Recommendations
As a temporary workaround, restrict access to or avoid using the
generate favicon from url() function until a fix is provided.Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Auto-Favicon