CVE-2026-70551

EUVD-2026-65518
A user who can read an existing remote VCS repository can replace its configured origin or supply an absolute VCS data URL.
SSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
JFROGCNA
8.5 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
jfrogartifactory
7.161.0 ≤
𝑥
< 7.161.19
CNA
jfrogartifactory
7.146.0 ≤
𝑥
< 7.146.36
CNA