KUNO CMS is a fully deployable full-stack blog application. In versions prior to 1.3.15, an SSRF (Server-Side Request Forgery) vulnerability exists in the Media module of the Kuno CMS administrative panel. A logged-in administrator can upload a specially crafted SVG file containing an external image reference, causing the server to initiate an outgoing connection to an arbitrary external URL. This can lead to information disclosure or internal network probing. Version 1.3.15 contains a fix for the issue.
History

Wed, 08 Oct 2025 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Kuno
Kuno kuno Cms
Vendors & Products Kuno
Kuno kuno Cms

Tue, 07 Oct 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 06 Oct 2025 22:00:00 +0000

Type Values Removed Values Added
Description KUNO CMS is a fully deployable full-stack blog application. In versions prior to 1.3.15, an SSRF (Server-Side Request Forgery) vulnerability exists in the Media module of the Kuno CMS administrative panel. A logged-in administrator can upload a specially crafted SVG file containing an external image reference, causing the server to initiate an outgoing connection to an arbitrary external URL. This can lead to information disclosure or internal network probing. Version 1.3.15 contains a fix for the issue.
Title Kuno CMS Vulnerable to Server-Side Request Forgery (SSRF) via Unsafe SVG Upload
Weaknesses CWE-20
CWE-434
CWE-918
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:L/SC:L/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-10-06T21:54:50.656Z

Updated: 2025-10-07T15:51:31.246Z

Reserved: 2025-09-30T19:43:49.900Z

Link: CVE-2025-61768

cve-icon Vulnrichment

Updated: 2025-10-07T15:51:25.775Z

cve-icon NVD

Status : Received

Published: 2025-10-06T22:15:37.273

Modified: 2025-10-06T22:15:37.273

Link: CVE-2025-61768

cve-icon Redhat

No data.