CVE-2025-10393: Miurla Morphic
Medium severity, CVSS 6.3. EPSS: 0.3% chance of exploitation in the next 30 days.
A flaw has been found in miurla morphic up to 0.4.5. This impacts the function fetchHtml of the file /api/advanced-search of the component HTTP Status Code 3xx Handler. This manipulation causes server-side request forgery. The attack is possible to be carried out remotely. The exploit has been published and may be used.
Affected products
- Miurla Morphic: version 0.4.0 only; version 0.4.1 only; version 0.4.2 only; version 0.4.3 only; version 0.4.4 only; version 0.4.5 only
Published 2025-09-14. Last modified 2026-06-17.