Impact
Miniflux version 2.3.0 through 2.3.3 contains a server‑side request forgery vulnerability that allows an authenticated user to configure a feed’s proxy_url to an arbitrary address. By pointing the proxy_url at loopback or other internal hosts, the application bypasses the FETCHER_ALLOW_PRIVATE_NETWORKS check and can issue proxy‑style requests to services inside the internal network. This grants the attacker the ability to probe internal ports, read data, and potentially execute lateral commands, exposing the internal network to enumeration and compromise.
Affected Systems
The vulnerability affects the Miniflux application as distributed by miniflux_project. All releases from 2.3.0 up to and including 2.3.3 are impacted. No specific operating system or environment restrictions are listed; the issue is inherent to the application logic in the mentioned version range.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. EPSS data is not available, so the current exploitation probability cannot be inferred from that metric. The vulnerability is not listed in the CISA KEV catalog. Because the flaw requires authenticated access, attackers must first compromise or log into a Miniflux instance. From there, the ability to change the proxy_url property provides broad internal network access, increasing the potential impact if the internal network hosts are sensitive or contain further exposes.
OpenCVE Enrichment