CVE-2026-15525

MEDIUM

kLOsk adloop write.py _validate_urls server-side request forgery

Title source: cna
STIX 2.1

Description

A vulnerability was detected in kLOsk adloop up to 0.9.0. This vulnerability affects the function _validate_urls of the file src/adloop/ads/write.py. Performing a manipulation of the argument final_url results in server-side request forgery. The attack may be initiated remotely. The exploit is now public and may be used. Upgrading to version 0.10.0 is able to resolve this issue. The patch is named 217399723e3a2fb39389e5355d49ed80aaf9ea7c. Upgrading the affected component is advised.

References (8)

Core 8
Core References
Vdb Entry, Technical Description vdb-entry technical-description
VDB-377854 | kLOsk adloop write.py _validate_urls server-side request forgery
https://vuldb.com/vuln/377854
Signature, Permissions Required signature permissions-required
VDB-377854 | CTI Indicators (IOB, IOC, IOA)
https://vuldb.com/vuln/377854/cti
Third Party Advisory third-party-advisory
CVE-2026-15525 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-15525
Third Party Advisory third-party-advisory
Submit #854528 | kLOsk adloop 0.9.0 Server-Side Request Forgery
https://vuldb.com/submit/854528
Exploit exploit issue-tracking
https://github.com/kLOsk/adloop/issues/41

Scores

CVSS v3 6.3
EPSS 0.0021
EPSS Percentile 12.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-918
Status published
Products (10)
kLOsk/adloop 0.1
kLOsk/adloop 0.10.0
kLOsk/adloop 0.2
kLOsk/adloop 0.3
kLOsk/adloop 0.4
kLOsk/adloop 0.5
kLOsk/adloop 0.6
kLOsk/adloop 0.7
kLOsk/adloop 0.8
kLOsk/adloop 0.9.0
Published Jul 13, 2026
Tracked Since Jul 13, 2026