Impact
The flaw in Mealie’s OpenID Connect avatar fetch allows an authenticated user to set a picture URL that is used during login. The service ignores the port when allow‑listing the provider hostname, enabling the attacker to instruct the server to issue GET requests to arbitrary ports on the provider’s internal address. This can leak internal network information or access services that are only reachable from within the internal network, compromising confidentiality and potentially permitting lateral movement. The vulnerability is limited to SSRF and does not provide direct code execution or privilege escalation on its own, but it can be a stepping stone to more severe attacks if the internal services are sensitive.
Affected Systems
Mealie, the recipe‑management application provided by mealie‑recipes, is affected in releases 3.26.0 through 3.28.0. Any installation running one of these versions with OIDC authentication enabled is vulnerable.
Risk and Exploitability
The CVSS score of 2.3 reflects a low severity impact when considered in isolation. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating no confirmed exploit evidence in the wild yet. However, because the attacker only needs a legitimate OIDC account to manipulate the picture URL, the threat is realistic in environments where such accounts exist. The attacker can trigger the vulnerable request on each login, making the attack repeatable over time. Although the risk appears limited, the potential to probe internal services should not be ignored.
OpenCVE Enrichment