PT-2026-8348 · Geekai · Geekai
R00Tuser
·
Published
2026-02-16
·
Updated
2026-02-16
·
CVE-2026-2558
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
GeekAI versions up to 4.2.4
Description
A flaw exists in GeekAI that allows for server-side request forgery. The issue is related to the
Download function within the api/handler/net handler.go file. Manipulation of the url argument in this function can lead to exploitation. Remote exploitation is possible, and an exploit has been published. The project was notified of the issue but has not yet responded.Recommendations
Versions prior to 4.2.4 are affected. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Geekai