PT-2026-40450 · Mosparo · Mosparo
Published
2026-05-12
·
Updated
2026-05-12
·
CVE-2026-41195
CVSS v3.1
5.0
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
mosparo versions prior to 1.4.13
Description
The automatic rule package source URL feature allows a project member with the editor role to store an attacker-controlled URL that the server subsequently fetches. Since the server follows http/https redirects and does not restrict private or loopback destinations, this creates a stored Server-Side Request Forgery (SSRF)—a flaw where the server is tricked into making requests to an unintended location—which can be used as an internal HTTP probing oracle to discover internal network services.
Recommendations
Update to version 1.4.13.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mosparo