CVE-2026-5016

HIGH

elecV2 elecV2P URL mock eAxios server-side request forgery

Title source: cna
STIX 2.1

Description

A vulnerability was identified in elecV2 elecV2P up to 3.8.3. This affects the function eAxios of the file /mock of the component URL Handler. Such manipulation of the argument req leads to server-side request forgery. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.

References (5)

Core 5
Core References
Vdb Entry, Technical Description vdb-entry technical-description
VDB-353901 | elecV2 elecV2P URL mock eAxios server-side request forgery
https://vuldb.com/vuln/353901
Signature, Permissions Required signature permissions-required
VDB-353901 | CTI Indicators (IOB, IOC, IOA)
https://vuldb.com/vuln/353901/cti
Third Party Advisory third-party-advisory
Submit #779181 | elecV2 <=3.8.3 SSRF
https://vuldb.com/submit/779181
Exploit exploit issue-tracking
https://github.com/elecV2/elecV2P/issues/202

Scores

CVSS v3 7.3
EPSS 0.0030
EPSS Percentile 21.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-918
Status published
Products (4)
elecV2/elecV2P 3.8.0
elecV2/elecV2P 3.8.1
elecV2/elecV2P 3.8.2
elecV2/elecV2P 3.8.3
Published Mar 28, 2026
Tracked Since Mar 29, 2026