CVE-2025-60541: Linshenkx Prompt Optimizer
High severity, CVSS 7.3. EPSS: 0.2% chance of exploitation in the next 30 days.
A Server-Side Request Forgery (SSRF) in the /api/proxy/ component of linshenkx prompt-optimizer v1.3.0 to v1.4.2 allows attackers to scan internal resources via a crafted request.
Affected products
- Linshenkx Prompt Optimizer: from 1.3.0, up to and including 1.4.2
Published 2025-11-06. Last modified 2026-06-17.