top of page
perceptive_background_267k.jpg

MoviePilot v2 contains a server-side request forgery vulnerability in the image proxy endpoint that allows authenticated attackers to request arbitrary URLs by …

Published:

28 May 2026 at 22:00:00

Alert date:

29 May 2026 at 19:07:04

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Data Breach & Exfiltration

MoviePilot v2 contains a server-side request forgery (SSRF) vulnerability in its image proxy endpoint. The vulnerability allows authenticated attackers to make arbitrary requests by providing a resource_token cookie and a URL with an allowed domain. The SecurityUtils.is_safe_url function only performs domain checking without blocking private, loopback, or link-local addresses. This enables attackers to bypass internal network protections and enumerate internal services like Jellyfin, Emby, or Plex. The vulnerability can be exploited to exfiltrate data from internal network resources.

Technical details

Mitigation steps:

Affected products:

MoviePilot

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page