CVE 5.3 MEDIUM

ThinkDashboard: Blind Server-Side Request Forgery (SSRF) vulnerability in /api/ping Endpoint_CVE-2025-64327

5.3 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Description

ThinkDashboard is a self-hosted bookmark dashboard built with Go and vanilla JavaScript. Versions 0.6.7 and below contain a Blind Server-Side Request Forgery (SSRF) vulnerability, in its `/api/ping?url= endpoint`. This allows an attacker to make arbitrary requests to internal or external hosts. This can include discovering ports open on the local machine, hosts on the local network, and ports open on the hosts on the internal network. This issue is fixed in version 0.6.8.

Basic Information

ID CVE-2025-64327
Source GitHub_M
Published Nov 6, 2025 at 21:07
Modified Nov 6, 2025 at 21:29

Affected Product

Vendor MatiasDesuu
Product ThinkDashboard
Version < 0.6.8
Affected Versions MatiasDesuu ThinkDashboard < 0.6.8

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.