-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from error message leakage in the image download validation process. The commit diff shows the vulnerable code was in the validate_remote_image method where exception details were returned to users. This function handles external URL processing and error reporting, making it the entry point for SSRF exploitation through error message introspection. The patch specifically modifies this function to replace detailed exceptions with generic messages, confirming its role in the vulnerability.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| inventree | pip | < 0.16.5 | 0.16.5 |
Ongoing coverage of React2Shell