CVE-2026-94028 | mealie-recipes Mealie up to 3.25.1 Recipe Action Trigger controller_group_recipe_actions.py payload.model_dump url server-side request forgery (Issue 7831)

SecurityVulns

A vulnerability labeled as problematic has been found in mealie-recipes Mealie up to 3.25.1. Affected is the function payload.model_dump of the file mealie/routes/households/controller_group_recipe_actions.py of the component Recipe Action Trigger. Executing a manipulation of the argument url can lead to server-side request forgery.

This vulnerability is handled as CVE-2026-94028. The attack can be executed remotely. Additionally, an exploit exists.

The affected component should be upgraded.VulDB Recent EntriesRead More