๐Ÿ” CVE Alert

CVE-2026-72606

HIGH 7.5

Pinry Pinry - Server-Side Request Forgery

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

A server-side request forgery vulnerability in Pinry through 2.1.13 allows unauthenticated remote attackers to make the server issue HTTP requests to arbitrary internal or external hosts via the pin-from-URL feature. The feature passes the user-supplied URL directly to requests.get() without host or IP validation, and ALLOW_NEW_REGISTRATIONS defaults to true enabling anonymous triggering. An attacker can reach internal services or cloud metadata endpoints from the server.

CWE CWE-918
Vendor pinry
Product pinry
Published Aug 11, 2026
Last Updated Aug 11, 2026
Stay Ahead of the Next One

Get instant alerts for pinry pinry

Be the first to know when new high vulnerabilities affecting pinry pinry are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Pinry / Pinry
0 โ‰ค 2.1.13

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/pinry/pinry

Credits

Xumoyun Obidjonov