Description
A vulnerability was determined in mifi lossless-cut up to 3.69.0. Affected by this issue is some unknown functionality of the file src/main/httpServer.ts of the component Built-in HTTP API Service. Executing a manipulation can lead to server-side request forgery. The attack requires access to the local network. This attack is characterized by high complexity. The exploitation is known to be difficult. The exploit has been publicly disclosed and may be utilized. This patch is called 260802348955231442c4bae6c2d9d8ede947af0a. It is best practice to apply a patch to resolve this issue. The project maintainer provides this view: "I'm not sure that this is a critical vulnerability, because it is behind an experimental CLI flag and the NTLM behavior isn't really a LosslessCut bug." The CVSS vector reflects the high level of pre-requisites.
Published: 2026-08-09
Score: 2.3 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A server‑side request forgery vulnerability exists in the built‑in HTTP API service of mifi lossless‑cut. The flaw allows an attacker to instruct the service to make arbitrary HTTP requests to internal or external hosts, potentially exposing sensitive data or enabling further attacks. The vulnerability is enabled by a feature behind an experimental command‑line flag and could involve NTLM authentication to internal resources.

Affected Systems

The issue affects mifi lossless‑cut versions up to 3.69.0. Any installation that uses the built‑in HTTP API service with the experimental flag enabled is susceptible.

Risk and Exploitability

The CVSS base score is 2.3, reflecting a low overall impact. Exploitation requires access to the local network, has high complexity, and is known to be difficult. No EPSS information is available, and the CVE is not listed in the CISA KEV catalog. However, the vulnerability has been publicly disclosed, so the risk is moderate in environments where the API service is reachable from untrusted hosts.

Generated by OpenCVE AI on August 9, 2026 at 13:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update lossless‑cut to the patched version from commit 260802348955231442c4bae6c2d9d8ede947af0a or any newer release that removes the vulnerable code.
  • If the HTTP API service is not required, disable or delete the experimental CLI flag that exposes it.
  • Restrict network access to the machine running lossless‑cut by firewalling the port used by the HTTP API so that only trusted hosts can contact it.

Generated by OpenCVE AI on August 9, 2026 at 13:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 09 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in mifi lossless-cut up to 3.69.0. Affected by this issue is some unknown functionality of the file src/main/httpServer.ts of the component Built-in HTTP API Service. Executing a manipulation can lead to server-side request forgery. The attack requires access to the local network. This attack is characterized by high complexity. The exploitation is known to be difficult. The exploit has been publicly disclosed and may be utilized. This patch is called 260802348955231442c4bae6c2d9d8ede947af0a. It is best practice to apply a patch to resolve this issue. The project maintainer provides this view: "I'm not sure that this is a critical vulnerability, because it is behind an experimental CLI flag and the NTLM behavior isn't really a LosslessCut bug." The CVSS vector reflects the high level of pre-requisites.
Title mifi lossless-cut Built-in HTTP API Service httpServer.ts server-side request forgery
First Time appeared Mifi
Mifi lossless-cut
Weaknesses CWE-918
CPEs cpe:2.3:a:mifi:lossless-cut:*:*:*:*:*:*:*:*
Vendors & Products Mifi
Mifi lossless-cut
References
Metrics cvssV2_0

{'score': 1.8, 'vector': 'AV:A/AC:H/Au:N/C:P/I:N/A:N/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 3.1, 'vector': 'CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Mifi Lossless-cut
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-09T12:15:39.398Z

Reserved: 2026-08-08T16:35:24.389Z

Link: CVE-2026-19352

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-09T13:30:04Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)