CVE-2023-25230: Loonflow Project Loonflow
Medium severity, CVSS 4.9. EPSS: 0.7% chance of exploitation in the next 30 days.
A Server-Side Request Forgery (SSRF) in loonflow r2.0.14 allows attackers to force the application to make arbitrary requests via manipulation of the hook_url parameter.
Affected products
- Loonflow Project Loonflow: version r2.0.14 only
Published 2023-03-07. Last modified 2026-06-17.