Description
A vulnerability was determined in SveltyCMS 0.0.6. This issue affects some unknown processing of the file /mediagallery/upload-media of the component File Upload Endpoint. Executing a manipulation can lead to server-side request forgery. The attack can be launched remotely. This patch is called 05b4f9efeb79e9d72a693232334d7529687f896f. It is best practice to apply a patch to resolve this issue.
Published: 2026-09-18
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Server-side request forgery
Action: Immediate Patch
AI Analysis

Impact

A vulnerability in SveltyCMS 0.0.6 allows an attacker to manipulate the /mediagallery/upload-media endpoint so that the server initiates a request to an arbitrary URL specified by the attacker. This results in a server‑side request forgery (SSRF) that can expose internal network resources or send data to external destinations without the user’s consent. The flaw does not directly grant code execution or privilege escalation, but it can be leveraged to pivot further attacks or exfiltrate sensitive data.

Affected Systems

SveltyCMS version 0.0.6, specifically the file upload component located at /mediagallery/upload-media. The vendor name is SveltyCMS and the affected component is the File Upload Endpoint.

Risk and Exploitability

The CVSS score of 5.3 indicates a medium risk level. The EPSS score is <1%, and the flaw is not listed in CISA KEV, indicating no known active exploitation. The attack vector is remote, as an attacker can trigger the vulnerable endpoint by sending a specially crafted request. Exploitation would require an authenticated or unauthenticated user to possess the ability to upload media, but no other special conditions are described.

Generated by OpenCVE AI on September 19, 2026 at 18:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor patch that incorporates commit 05b4f9efeb79e9d72a693232334d7529687f896f to fix the SSRF in the upload‑media endpoint.
  • Re‑configure the server’s outbound network policy to limit the SveltyCMS process to only the hosts and ports required for normal operation, thereby mitigating the impact of any future SSRF flaws.
  • Update the application code for the upload‑media endpoint to validate against disallowed protocols and hostnames, ensuring that arbitrary URLs cannot be supplied by the client.

Generated by OpenCVE AI on September 19, 2026 at 18:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in SveltyCMS 0.0.6. This issue affects some unknown processing of the file /mediagallery/upload-media of the component File Upload Endpoint. Executing a manipulation can lead to server-side request forgery. The attack can be launched remotely. This patch is called 05b4f9efeb79e9d72a693232334d7529687f896f. It is best practice to apply a patch to resolve this issue.
Title SveltyCMS File Upload Endpoint upload-media server-side request forgery
First Time appeared Sveltycms
Sveltycms sveltycms
Weaknesses CWE-918
CPEs cpe:2.3:a:sveltycms:sveltycms:*:*:*:*:*:*:*:*
Vendors & Products Sveltycms
Sveltycms sveltycms
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:ND/RL:OF/RC:C'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X'}


Subscriptions

Sveltycms Sveltycms
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-22T14:39:11.431Z

Reserved: 2026-09-18T08:26:52.415Z

Link: CVE-2026-93506

cve-icon Vulnrichment

Updated: 2026-09-22T14:39:07.811Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T15:17:19.410

Modified: 2026-09-22T15:17:22.973

Link: CVE-2026-93506

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T19:00:15Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)