๐Ÿ” CVE Alert

CVE-2026-107273

MEDIUM 4.3

Gophish 0.11.0 through 0.12.1 SSRF via POST /api/import/site

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

Gophish 0.11.0 through 0.12.1 contains a server-side request forgery vulnerability that allows authenticated low-privileged users to reach loopback and private hosts via POST /api/import/site. Attackers can submit internal URLs, which the default dialer deny list does not block, to read service responses and enumerate internal hosts and ports through error messages.

CWE CWE-918
Vendor gophish
Product gophish
Published Oct 7, 2026
Stay Ahead of the Next One

Get instant alerts for gophish gophish

Be the first to know when new medium vulnerabilities affecting gophish gophish are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None

Affected Versions

gophish / gophish
0.11.0 โ‰ค 0.12.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
blog.ostorlab.co: https://blog.ostorlab.co/gophish-0121-manual-review-agentic-deep-scan.html github.com: https://github.com/gophish/gophish/blob/b1648f0759c6d57ac989157c55d8b47c40254fe6/dialer/dialer.go#L82-L86 github.com: https://github.com/gophish/gophish/blob/b1648f0759c6d57ac989157c55d8b47c40254fe6/controllers/api/import.go#L102-L125 github.com: https://github.com/gophish/gophish vulncheck.com: https://www.vulncheck.com/advisories/gophish-0.11.0-through-0.12.1-ssrf-via-post-api-import-site

Credits

Sohaib Harraoui (Ostorlab)