VDB
Sign up
HIGH7.5

GHSA-hxgx-584x-vwm8

Appwrite Server-Side Request Forgery vulnerability

Details

Appwrite up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component `/v1/avatars/favicon`. This vulnerability allows attackers to access network resources and sensitive information via a crafted GET request.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/appwrite/server-ce
Introduced in: 0

No fixed version published yet for appwrite/server-ce (composer). Pin to a known-safe version or switch to an alternative.

References