{"id":"GHSA-gmxh-hjfv-qc2w","summary":"Koillection has an authenticated Server-Side Request Forgery issue","details":"An authenticated Server-Side Request Forgery (SSRF) in the custom scraper subsystem component of Benjamin Jonard Koillection v1.8.0 allows attackers to scan internal resources via supplying a crafted URL.","aliases":["CVE-2026-50888"],"modified":"2026-08-27T17:10:37.018291Z","published":"2026-06-15T21:30:41Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-08-27T16:44:47Z","nvd_published_at":"2026-06-15T20:16:31Z","cwe_ids":["CWE-918"],"severity":"HIGH"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-50888"},{"type":"WEB","url":"https://github.com/benjaminjonard/koillection/pull/1599"},{"type":"WEB","url":"https://github.com/benjaminjonard/koillection/commit/4d445e21c631c26070f19fe8ec086a2939767ae0"},{"type":"WEB","url":"https://gist.github.com/pyuysig/d60273c1c346257ceddbf8da7134bae7"},{"type":"PACKAGE","url":"https://github.com/benjaminjonard/koillection"},{"type":"WEB","url":"https://github.com/benjaminjonard/koillection/releases/tag/1.8.4"}],"affected":[{"package":{"name":"koillection/koillection","ecosystem":"Packagist","purl":"pkg:composer/koillection/koillection"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.8.4"}]}],"versions":["1.1.7","1.2.0","1.2.1","1.2.2","1.2.3","1.2.4","1.2.5","1.3.0","1.3.1","1.3.10","1.3.11","1.3.12","1.3.13","1.3.14","1.3.15","1.3.16","1.3.17","1.3.18","1.3.2","1.3.3","1.3.4","1.3.5","1.3.6","1.3.7","1.3.8","1.3.9","1.4.0","1.4.1","1.4.10","1.4.11","1.4.12","1.4.13","1.4.2","1.4.3","1.4.4","1.4.5","1.4.6","1.4.7","1.4.8","1.4.9","1.5.0","1.5.1","1.5.10","1.5.11","1.5.12","1.5.13","1.5.14","1.5.15","1.5.2","1.5.3","1.5.4","1.5.5","1.5.6","1.5.7","1.5.8","1.5.9","1.6.0","1.6.1","1.6.10","1.6.11","1.6.12","1.6.13","1.6.14","1.6.15","1.6.16","1.6.17","1.6.18","1.6.2","1.6.3","1.6.4","1.6.5","1.6.6","1.6.7","1.6.8","1.6.9","1.7.0","1.7.1","1.8.0","1.8.3","v1.0.0","v1.0.1","v1.0.2","v1.0.3","v1.0.4","v1.1.0","v1.1.1","v1.1.2","v1.1.3","v1.1.4","v1.1.5","v1.1.6"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-gmxh-hjfv-qc2w/GHSA-gmxh-hjfv-qc2w.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"}]}