CyberRota Analysis
AI-GeneratedA server-side request forgery vulnerability in Friendica allows authenticated users with self-registered accounts to exploit the link-preview endpoint, enabling them to probe internal network services without restrictions. This could lead to unauthorized access to sensitive internal resources or cloud metadata services. Organizations using Friendica, particularly those with self-registered user capabilities, should prioritize addressing this vulnerability to mitigate potential internal network exposure.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A server-side request forgery vulnerability in Friendica through the 2026.08-dev branch allows authenticated users with a free self-registered account to probe internal network services via the link-preview endpoint. The endpoint fetches any user-supplied URL without applying an internal IP deny list. An attacker can use this to scan the internal network or access cloud metadata services.