CVE-2026-28680 PUBLISHED

Ghostfolio: Full-Read SSRF in Manual Asset Import

Assigner: GitHub_M
Reserved: 02.03.2026 Published: 06.03.2026 Updated: 06.03.2026

Ghostfolio is an open source wealth management software. Prior to version 2.245.0, an attacker can exploit the manual asset import feature to perform a full-read SSRF, allowing them to exfiltrate sensitive cloud metadata (IMDS) or probe internal network services. This issue has been patched in version 2.245.0.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
CVSS Score: 9.3

Product Status

Vendor ghostfolio
Product ghostfolio
Versions
  • Version < 2.245.0 is affected

References

Problem Types

  • CWE-918: Server-Side Request Forgery (SSRF) CWE