🔐 CVE Alert

CVE-2026-59231

UNKNOWN 0.0

Server-Side Request Forgery in Pentestify PDF export via unvalidated image URLs

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Server-Side Request Forgery in the PDF export component in maalfer Pentestify before 1.1.0 allows authenticated users to cause outbound HTTP GET requests from the server to arbitrary attacker-chosen destinations via unvalidated URLs stored in the finding images field or the report client_logo field, which the server-side headless browser fetches while rendering the report.

CWE CWE-918
Vendor ccyl13
Product pentestify
Published Jul 31, 2026
Stay Ahead of the Next One

Get instant alerts for ccyl13 pentestify

Be the first to know when new unknown vulnerabilities affecting ccyl13 pentestify are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

ccyl13 / Pentestify
0 < 1.1.0

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/ccyl13/Pentestify/commit/a058a22b42c6311895622645265df79a60265b1d github.com: https://github.com/ccyl13/Pentestify/releases/tag/v1.1.1 secur0.com: https://secur0.com/en/cna/cve-list/cve-2026-59231-ssrf-in-pentestify-via-unvalidated-image-urls-cve-id-cve-2026-59231

Credits

Marcos Turrión García (marcosturriongarcia2005) Xoán M. Otero Jorge Secur0 CNA Mario Álvarez Fernández (maalfer) Cristian Fernandez Cornejo