๐Ÿ” CVE Alert

CVE-2026-3189

LOW 3.1

feiyuchuixue sz-boot-parent download server-side request forgery

CVSS Score
3.1
EPSS Score
0.0%
EPSS Percentile
0th

A weakness has been identified in feiyuchuixue sz-boot-parent up to 1.3.2-beta. This vulnerability affects unknown code of the file /api/admin/common/files/download. Executing a manipulation of the argument url can lead to server-side request forgery. The attack can be executed remotely. Attacks of this nature are highly complex. It is stated that the exploitability is difficult. Upgrading to version 1.3.3-beta is able to resolve this issue. This patch is called aefaabfd7527188bfba3c8c9eee17c316d094802. Upgrading the affected component is advised. The project was informed beforehand and acted very professional: "We have added a URL protocol whitelist validation to the file download interface, allowing only http and https protocols."

CWE CWE-918
Vendor feiyuchuixue
Product sz-boot-parent
Published Feb 25, 2026
Last Updated Feb 25, 2026
Stay Ahead of the Next One

Get instant alerts for feiyuchuixue sz-boot-parent

Be the first to know when new low vulnerabilities affecting feiyuchuixue sz-boot-parent are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N/E:X/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

feiyuchuixue / sz-boot-parent
1.3.2-beta

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/?id.347747 vuldb.com: https://vuldb.com/?ctiid.347747 vuldb.com: https://vuldb.com/?submit.754042 github.com: https://github.com/yuccun/CVE/blob/main/sz-boot-parent-SSRF_and_Arbitrary_File_Read.md github.com: https://github.com/feiyuchuixue/sz-boot-parent/commit/aefaabfd7527188bfba3c8c9eee17c316d094802 github.com: https://github.com/feiyuchuixue/sz-boot-parent/releases/tag/v1.3.3-beta github.com: https://github.com/feiyuchuixue/sz-boot-parent/

Credits

๐Ÿ” yuccun (VulDB User)