HarborGuard / CVE
Back to search
CRITICALCVE-2026-28680Published Modified CNA GitHub_M

CVE-2026-28680: Ghostfolio: Full-Read SSRF in Manual Asset Import

Ghostfolio is an open source wealth management software. Prior to version 2.245.0, an attacker can exploit the manual asset import feature to perform a full-read SSRF, allowing them to exfiltrate sensitive cloud metadata (IMDS) or probe internal network services. This issue has been patched in version 2.245.0.

Metrics

CVSS v3.1
9.3
Severity
CRITICAL
Fixed in
Affected Products
1
Affected packages
  • ghostfolio / ghostfolio
    < 2.245.0
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N