CVE-2026-72591: Gabehf Koito
High severity, CVSS 7.7. EPSS: 0.4% chance of exploitation in the next 30 days.
A server-side request forgery (SSRF) vulnerability in gabehf/Koito through v0.3.2 allows an authenticated user to make the server perform HTTP requests to arbitrary internal or external hosts by supplying a crafted image_url value in the PATCH /apis/web/v1/album/{id}/image endpoint.
Affected products
- Gabehf Koito: up to and including 0.3.2
Published 2026-08-10. Last modified 2026-08-28.