← Back

CVE-2025-52186

nvd nist
Published: Nov 13, 2025Modified: Jan 9, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Exploitability: 3.9 / Impact: 2.5
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

Lichess lila before commit 11b4c0fb00f0ffd823246f839627005459c8f05c (2025-06-02) contains a Server-Side Request Forgery (SSRF) vulnerability in the game export API. The players parameter is passed directly to an internal HTTP client without validation, allowing remote attackers to force the server to send HTTP requests to arbitrary URLs

Affected (1)

Products: Lichess: Lila
1 product
Lila
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 2025-06-02

References (2)

Timeline

No history available yet.