CVE-2026-107273: Gophish 0.11.0 through 0.12.1 SSRF via POST /api/import/site
Gophish 0.11.0 through 0.12.1 contains a server-side request forgery vulnerability that allows authenticated low-privileged users to reach loopback and private hosts via POST /api/import/site. Attackers can submit internal URLs, which the default dialer deny list does not block, to read service responses and enumerate internal hosts and ports through error messages.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated low-privileged Gophish user can exploit it. No user interaction is required.
What internal resources can an attacker target?
An attacker can submit URLs for loopback and private hosts through POST /api/import/site. The affected default dialer deny list does not block these targets.
What information can exploitation expose?
The issue can allow reading responses from reachable internal services. Error messages can also be used to enumerate internal hosts and ports.