CVE-2026-19927 | OpenBoxes up to 0.9.7 Product Upload Endpoint ProductController.groovy upload params.url server-side request forgery (GHSA-828r-3vx8-65wx)

SecurityVulns

A vulnerability marked as critical has been reported in OpenBoxes up to 0.9.7. The impacted element is the function Upload of the file grails-app/controllers/org/pih/warehouse/product/ProductController.groovy of the component Product Upload Endpoint. Performing a manipulation of the argument params.url results in server-side request forgery.

This vulnerability is reported as CVE-2026-19927. The attack is possible to be carried out remotely. Moreover, an exploit is present.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More