


Perceptive Security
SOC/SIEM Consultancy

Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenticated user can trigger server-side reque…
Published:
17 April 2026 at 22:00:00
Alert date:
18 April 2026 at 01:02:17
Source:
nvd.nist.gov
Web Technologies
Movary, a self-hosted movie tracking web application, contains a Server-Side Request Forgery (SSRF) vulnerability in versions prior to 0.71.1. The vulnerability exists in the POST /settings/jellyfin/server-url-verify endpoint which accepts user-controlled URLs without proper validation. Authenticated users can exploit this to make server-side requests to arbitrary internal targets, enabling internal network reconnaissance, host discovery, port scanning, and service fingerprinting. The vulnerability could potentially be used to access internal administrative services or cloud metadata endpoints not directly accessible from external networks. The issue has been fixed in version 0.71.1.
Technical details
Mitigation steps:
Affected products:
Movary
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-40348
https://github.com/leepeuker/movary/commit/d459b3513293d41254f7093aef07010a8e5dcf04
https://github.com/leepeuker/movary/pull/751
https://github.com/leepeuker/movary/releases/tag/0.71.1
https://github.com/leepeuker/movary/security/advisories/GHSA-2m2v-v563-qqvj
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
