Impact
A vulnerability exists in the Mealie component that allows manipulation of the URL parameter in the payload.model_dump function, enabling an attacker to invoke arbitrary outbound requests from the server. This server‑side request forgery (CWE‑918) is remotely exploitable and an exploit is publicly available. Upgrading to 3.26.0 addresses the issue.
Affected Systems
All Mealie deployments running versions up to 3.25.1 are vulnerable. The compromise arises in the Recipe Action Trigger controller_group_recipe_actions.py module. Updating the application to version 3.26.0 or later, which includes commit fb221a..., removes the vulnerable code.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate risk, and the lack of an EPSS score or KEV listing reduces our current intelligence, but the public availability of an exploit and the remote attack vector mean that any exposed instance could be targeted. Until a patch is applied, the vulnerability remains exploitable and presents a medium likelihood of use in a targeted attack.
OpenCVE Enrichment