Junglewise Threat Intelligence

CVE-2026-15525: kLOsk adloop SSRF in _validate_urls

CVE-2026-15525 · Severity: medium · CVSS 6.3 · Published 2026-07-13

Executive brief

kLOsk adloop, an AI command center for Google Ads and Analytics, is vulnerable to a security flaw in how it validates web addresses. An attacker can manipulate specific URL parameters to force the server to make unauthorized requests to internal systems or external sites. This could lead to the exposure of sensitive internal data or unauthorized access to private network resources.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in kLOsk adloop versions up to 0.9.0. The flaw is located in the `_validate_urls` function within `src/adloop/ads/write.py`, where the application fails to properly validate the scheme and host of the `final_url` argument. A remote attacker with low privileges can provide a malicious URL, causing the server to perform unintended requests. This can be used to access internal metadata services, loopback interfaces, or private network ranges. The issue is resolved in version 0.10.0 by implementing an SSRF guard that rejects private and loopback IP ranges and re-checks redirects.

Affected products

  • kLOsk adloop up to 0.9.0

Timeline

  • 2026-07-06: patched: Patch 217399723e3a2fb39389e5355d49ed80aaf9ea7c committed
  • 2026-07-13: advisory: NVD publication date

References