CVE-2026-28680

CRITICAL

ghostfolio < 2.245.0 - Server-Side Request Forgery via Manual Asset Import Feature

Title source: llm
STIX 2.1

Description

Ghostfolio is an open source wealth management software. Prior to version 2.245.0, an attacker can exploit the manual asset import feature to perform a full-read SSRF, allowing them to exfiltrate sensitive cloud metadata (IMDS) or probe internal network services. This issue has been patched in version 2.245.0.

References (2)

Core 2

Scores

CVSS v3 9.3
EPSS 0.0023
EPSS Percentile 13.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-918
Status published
Products (1)
ghostfol/ghostfolio < 2.245.0
Published Mar 06, 2026
Tracked Since Mar 06, 2026