github.com
https://github.com/mautic/mautic CVE-2025-9821
LOW
SSRF via webhook function
Record summary
CVE-2025-9821 has a selected CVSS score of 2.7 (low).
Description
SummaryUsers with webhook permissions can conduct SSRF via webhooks. If they have permission to view the webhook logs, the (partial) request response is also disclosed DetailsWhen sending webhooks, the destination is not validated, causing SSRF. ImpactBypass of firewalls to interact with internal services. See https://owasp.org/Top10/A10_2021-Server-Side_Request_Forgery_%28SSRF%29/ for more potential impact. Resources https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html for more information on SSRF and its fix.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 3, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | >= 4.4.0 to ≤ < 4.4.17 | affected |
| >= 5.0.0-alpha to ≤ < 5.2.8 | affected | ||
| >= 6.0.0-alpha to ≤ < 6.0.5 | affected | ||
mautic/coreBrowse Packagist / mautic/core | GitHub Advisory | 4.4.0 to < 4.4.17 · Fixed in 4.4.17 | affected |
| 5.0.0-alpha to < 5.2.8 · Fixed in 5.2.8 | affected | ||
| 6.0.0-alpha to < 6.0.5 · Fixed in 6.0.5 | affected |
References
5github.com
https://github.com/mautic/mautic/commit/6084f6de4c88d1aeb5f6c73ea4fe1b09c98ea52b github.com
https://github.com/mautic/mautic/commit/dc5bb1466c9a48fd34768dc8ff5888716b2916ba github.com
https://github.com/mautic/mautic/security/advisories/GHSA-hj6f-7hp7-xg69 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-9821