CVE-2026-61520
HIGHSimpleMachines - Simple Machines Forum SSRF via Image Proxy
Title source: ruleDescription
Simple Machines Forum 2.1 prior to commit 4bf35cf and 3.0 prior to commit b4d23df contains a server-side request forgery vulnerability in the image proxy that allows authenticated attackers to trigger internal HTTP requests by embedding attacker-controlled URLs in BBCode image tags, which the proxy fetches without validating resolved destination IPs against private address ranges, loopback, or link-local addresses. Attackers can leverage SMF's automatic HMAC signature generation for any embedded image URL to obtain valid signed proxy requests targeting internal services such as cloud instance metadata endpoints, internal web applications, and container network services.
References (3)
Core 3
Core References
Patch patch
Patch Commit (v2.1)
https://github.com/SimpleMachines/SMF/commit/4bf35cf9e45573a5f55a6f52995086c1da89c096
Patch patch
Patch Commit (v3.0)
https://github.com/SimpleMachines/SMF/commit/b4d23dfd74a511587c605f9d294cefc3a75b4b26
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/simple-machines-forum-ssrf-via-image-proxy
Scores
CVSS v3
7.7
EPSS
0.0025
EPSS Percentile
16.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-918
Status
published
Products (4)
SimpleMachines/SMF
2.1.0 - 2.1.7
SimpleMachines/SMF
3.0.0
SimpleMachines/SMF
4bf35cf9e45573a5f55a6f52995086c1da89c096
SimpleMachines/SMF
b4d23dfd74a511587c605f9d294cefc3a75b4b26
Published
Jul 14, 2026
Tracked Since
Jul 15, 2026