CVE-2026-50888: Koillection has an authenticated Server-Side Request Forgery issue
(updated )
An authenticated Server-Side Request Forgery (SSRF) in the custom scraper subsystem component of Benjamin Jonard Koillection v1.8.0 allows attackers to scan internal resources via supplying a crafted URL.
References
- gist.github.com/pyuysig/d60273c1c346257ceddbf8da7134bae7
- github.com/advisories/GHSA-gmxh-hjfv-qc2w
- github.com/benjaminjonard/koillection/commit/4d445e21c631c26070f19fe8ec086a2939767ae0
- github.com/benjaminjonard/koillection/pull/1599
- github.com/benjaminjonard/koillection/releases/tag/1.8.4
- nvd.nist.gov/vuln/detail/CVE-2026-50888
Code Behaviors & Features
Detect and mitigate CVE-2026-50888 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →