KUNO CMS is a fully deployable full-stack blog application. In versions prior to 1.3.15, an SSRF (Server-Side Request Forgery) vulnerability exists in the Media module of the Kuno CMS administrative panel. A logged-in administrator can upload a specially crafted SVG file containing an external image reference, causing the server to initiate an outgoing connection to an arbitrary external URL. This can lead to information disclosure or internal network probing. Version 1.3.15 contains a fix for the issue.
History

Mon, 06 Oct 2025 22:00:00 +0000

Type Values Removed Values Added
Description KUNO CMS is a fully deployable full-stack blog application. In versions prior to 1.3.15, an SSRF (Server-Side Request Forgery) vulnerability exists in the Media module of the Kuno CMS administrative panel. A logged-in administrator can upload a specially crafted SVG file containing an external image reference, causing the server to initiate an outgoing connection to an arbitrary external URL. This can lead to information disclosure or internal network probing. Version 1.3.15 contains a fix for the issue.
Title Kuno CMS Vulnerable to Server-Side Request Forgery (SSRF) via Unsafe SVG Upload
Weaknesses CWE-20
CWE-434
CWE-918
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:L/SC:L/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-10-06T21:54:50.656Z

Reserved: 2025-09-30T19:43:49.900Z

Link: CVE-2025-61768

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-10-06T22:15:37.273

Modified: 2025-10-06T22:15:37.273

Link: CVE-2025-61768

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.