CVE-2023-27159: Appwrite
High severity, CVSS 7.5. EPSS: 36.4% chance of exploitation in the next 30 days.
Appwrite up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /v1/avatars/favicon. This vulnerability allows attackers to access network resources and sensitive information via a crafted GET request.
Affected products
- Appwrite Appwrite: up to and including 1.2.1
Published 2023-03-31. Last modified 2026-07-09.