LNbits is a Lightning wallet and accounts system. A Server-Side Request Forgery (SSRF) vulnerability has been discovered in LNbits' LNURL authentication handling functionality. When processing LNURL authentication requests, the application accepts a callback URL parameter and makes an HTTP request to that URL using the httpx library with redirect following enabled. The application doesn't properly validate the callback URL, allowing attackers to specify internal network addresses and access internal resources.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-10023 LNbits Lightning Network Payment System Vulnerable to Server-Side Request Forgery via LNURL Authentication Callback
Github GHSA Github GHSA GHSA-qp8j-p87f-c8cc LNbits Lightning Network Payment System Vulnerable to Server-Side Request Forgery via LNURL Authentication Callback
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 08 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Lnbits
Lnbits lnbits
CPEs cpe:2.3:a:lnbits:lnbits:*:*:*:*:*:*:*:*
Vendors & Products Lnbits
Lnbits lnbits
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Mon, 07 Apr 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 06 Apr 2025 20:15:00 +0000

Type Values Removed Values Added
Description LNbits is a Lightning wallet and accounts system. A Server-Side Request Forgery (SSRF) vulnerability has been discovered in LNbits' LNURL authentication handling functionality. When processing LNURL authentication requests, the application accepts a callback URL parameter and makes an HTTP request to that URL using the httpx library with redirect following enabled. The application doesn't properly validate the callback URL, allowing attackers to specify internal network addresses and access internal resources.
Title Server-Side Request Forgery via LNURL Authentication Callback in LNbits Lightning Network Payment System
Weaknesses CWE-918
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-04-07T14:08:48.776Z

Reserved: 2025-04-01T21:57:32.953Z

Link: CVE-2025-32013

cve-icon Vulnrichment

Updated: 2025-04-07T14:08:24.722Z

cve-icon NVD

Status : Analyzed

Published: 2025-04-06T20:15:15.217

Modified: 2025-04-08T18:54:07.337

Link: CVE-2025-32013

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.