


Perceptive Security
SOC/SIEM Consultancy

MoviePilot v2 contains a server-side request forgery vulnerability in the image proxy endpoint that allows authenticated attackers to request arbitrary URLs by …
Published:
28 May 2026 at 22:00:00
Alert date:
29 May 2026 at 19:07:04
Source:
nvd.nist.gov
Web Technologies, Data Breach & Exfiltration
MoviePilot v2 contains a server-side request forgery (SSRF) vulnerability in its image proxy endpoint. The vulnerability allows authenticated attackers to make arbitrary requests by providing a resource_token cookie and a URL with an allowed domain. The SecurityUtils.is_safe_url function only performs domain checking without blocking private, loopback, or link-local addresses. This enables attackers to bypass internal network protections and enumerate internal services like Jellyfin, Emby, or Plex. The vulnerability can be exploited to exfiltrate data from internal network resources.
Technical details
Mitigation steps:
Affected products:
MoviePilot
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-10107
https://github.com/jxxghp/MoviePilot/commit/0b7854a0af8751160b68c43c46ded48d2bd8a212
https://github.com/jxxghp/MoviePilot/issues/5823
https://github.com/jxxghp/MoviePilot/releases/tag/v2.13.2
https://www.vulncheck.com/advisories/moviepilot-v2-ssrf-via-api-v1-system-img-proxy-endpoint
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
