CVE-2026-59231: Server-Side Request Forgery in Pentestify PDF export via unvalidated image URLs
Server-Side Request Forgery in the PDF export component in maalfer Pentestify before 1.1.0 allows authenticated users to cause outbound HTTP GET requests from the server to arbitrary attacker-chosen destinations via unvalidated URLs stored in the finding images field or the report clientlogo field, which the server-side headless browser fetches while rendering the report.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.1.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-59231?
CVE-2026-59231 has a risk score of 52, indicating a medium severity level.
How do I fix CVE-2026-59231?
To mitigate CVE-2026-59231, upgrade to the Pentestify version 1.1.1 or later, which addresses this vulnerability.
What component is affected by CVE-2026-59231?
CVE-2026-59231 affects the PDF export component in the maalfer Pentestify.
What type of vulnerability is CVE-2026-59231 classified as?
CVE-2026-59231 is classified as a Server-Side Request Forgery (SSRF) vulnerability.
Who is impacted by CVE-2026-59231?
Authenticated users of the maalfer Pentestify tool are impacted by CVE-2026-59231.