CVE-2026-28680

Ghostfolio is an open source wealth management software. Prior to version 2.245.0, an attacker can exploit the manual asset import feature to perform a full-read SSRF, allowing them to exfiltrate sensitive cloud metadata (IMDS) or probe internal network services. This issue has been patched in version 2.245.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ghostfol:ghostfolio:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-03-06 05:16

Updated : 2026-03-10 19:53


NVD link : CVE-2026-28680

Mitre link : CVE-2026-28680

CVE.ORG link : CVE-2026-28680


JSON object : View

Products Affected

ghostfol

  • ghostfolio
CWE
CWE-918

Server-Side Request Forgery (SSRF)