Impact
Heimdall for LinuxServer exposes a Server‑Side Request Forgery vulnerability through its /test_config and /get_stats endpoints. These endpoints invoke a GuzzleHttp client that does not impose IP restrictions, allowing an unauthenticated attacker who can trigger CSRF to force the server to send requests to arbitrary internal hosts and ports, including the metadata service at 169.254.169.254. The attacker can read response data and status information, effectively probing internal services and gathering data that could aid subsequent attacks.
Affected Systems
All LinuxServer Heimdall deployments running versions prior to an upstream fix are affected. Since the CVE provides no fixed version, administrators should treat all releases before an announced patch as vulnerable. The issue resides in the test configuration and statistics handling paths, which bypass the SSRF guard present in the ItemController.
Risk and Exploitability
The CVSS score of 3.4 classifies the vulnerability as low severity. Exploitation requires only a CSRF request to the unprotected endpoints, a technique that is relatively easy to execute once a user can embed malicious requests. The EPSS score is not reported and the vulnerability is not listed in the CISA KEV catalog, implying a low probability of widespread exploitation; however, the capability to use Heimdall as a proxy to probe internal systems could still be to attackers.
OpenCVE Enrichment