CVE-2025-45250
MEDIUMMrdoc < 0.95 - SSRF
Title source: ruleDescription
MrDoc v0.95 and before is vulnerable to Server-Side Request Forgery (SSRF) in the validate_url function of the app_doc/utils.py file.
Exploits (2)
Scores
CVSS v3
5.5
EPSS
0.0009
EPSS Percentile
24.9%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-918
Status
published
Products (1)
mrdoc/mrdoc
< 0.95
Published
May 06, 2025
Tracked Since
Feb 18, 2026