Description
A weakness has been identified in mealie-recipes Mealie up to 3.25.1. Affected is the function payload.model_dump of the file mealie/routes/households/controller_group_recipe_actions.py of the component Recipe Action Trigger. Executing a manipulation of the argument url can lead to server-side request forgery. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 3.26.0 is able to address this issue. This patch is called fb221afa258c8dd2c4ac95b1996c33ef9db3f477. The affected component should be upgraded.
Published: 2026-09-20
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Server‑side request forgery
Action: Patch
AI Analysis

Impact

A vulnerability exists in the Mealie component that allows manipulation of the URL parameter in the payload.model_dump function, enabling an attacker to invoke arbitrary outbound requests from the server. This server‑side request forgery (CWE‑918) is remotely exploitable and an exploit is publicly available. Upgrading to 3.26.0 addresses the issue.

Affected Systems

All Mealie deployments running versions up to 3.25.1 are vulnerable. The compromise arises in the Recipe Action Trigger controller_group_recipe_actions.py module. Updating the application to version 3.26.0 or later, which includes commit fb221a..., removes the vulnerable code.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate risk, and the lack of an EPSS score or KEV listing reduces our current intelligence, but the public availability of an exploit and the remote attack vector mean that any exposed instance could be targeted. Until a patch is applied, the vulnerability remains exploitable and presents a medium likelihood of use in a targeted attack.

Generated by OpenCVE AI on September 20, 2026 at 15:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Mealie to version 3.26.0 or later to eliminate the vulnerable payload.model_dump handling.
  • If an immediate upgrade is not possible, restrict the application's outbound HTTP traffic to a whitelist of approved domains or block all external requests from the Mealie service.
  • Apply an application‑level firewall or API gateway that validates and sanitizes outbound requests, ensuring that only allowed URLs can be requested by the Mealie service.

Generated by OpenCVE AI on September 20, 2026 at 15:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Mealie-recipes
Mealie-recipes mealie
Vendors & Products Mealie-recipes
Mealie-recipes mealie

Sun, 20 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in mealie-recipes Mealie up to 3.25.1. Affected is the function payload.model_dump of the file mealie/routes/households/controller_group_recipe_actions.py of the component Recipe Action Trigger. Executing a manipulation of the argument url can lead to server-side request forgery. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 3.26.0 is able to address this issue. This patch is called fb221afa258c8dd2c4ac95b1996c33ef9db3f477. The affected component should be upgraded.
Title mealie-recipes Mealie Recipe Action Trigger controller_group_recipe_actions.py payload.model_dump server-side request forgery
First Time appeared Mealie
Mealie mealie
Weaknesses CWE-918
CPEs cpe:2.3:a:mealie:mealie:*:*:*:*:*:*:*:*
Vendors & Products Mealie
Mealie mealie
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:P/I:N/A:N/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Mealie Mealie
Mealie-recipes Mealie
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-21T14:11:03.666Z

Reserved: 2026-09-19T17:08:20.244Z

Link: CVE-2026-94028

cve-icon Vulnrichment

Updated: 2026-09-21T14:10:55.856Z

cve-icon NVD

Status : Deferred

Published: 2026-09-20T13:17:46.903

Modified: 2026-09-21T15:17:37.543

Link: CVE-2026-94028

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T15:30:17Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)