HIGH 8.1
GHSA-gmxh-hjfv-qc2w
Koillection has an authenticated Server-Side Request Forgery issue
Quick fix
GHSA-gmxh-hjfv-qc2w — koillection/koillection: upgrade to the fixed version with the command below.
composer require koillection/koillection:^1.8.4 Details
An authenticated Server-Side Request Forgery (SSRF) in the custom scraper subsystem component of Benjamin Jonard Koillection v1.8.0 allows attackers to scan internal resources via supplying a crafted URL.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist / koillection/koillection
Introduced in:
0 Fixed in: 1.8.4 Fix
composer require koillection/koillection:^1.8.4 References
- https://nvd.nist.gov/vuln/detail/CVE-2026-50888 [ADVISORY]
- https://github.com/benjaminjonard/koillection/pull/1599 [WEB]
- https://github.com/benjaminjonard/koillection/commit/4d445e21c631c26070f19fe8ec086a2939767ae0 [WEB]
- https://gist.github.com/pyuysig/d60273c1c346257ceddbf8da7134bae7 [WEB]
- https://github.com/benjaminjonard/koillection [PACKAGE]
- https://github.com/benjaminjonard/koillection/releases/tag/1.8.4 [WEB]