CVE-2026-107273
EUVD-2026-9440407.10.2026, 16:17
Gophish 0.11.0 through 0.12.1 contains a server-side request forgery vulnerability that allows authenticated low-privileged users to reach loopback and private hosts via POST /api/import/site. Attackers can submit internal URLs, which the default dialer deny list does not block, to read service responses and enumerate internal hosts and ports through error messages.
Awaiting analysis
This vulnerability is currently awaiting analysis.
References