Junglewise Threat Intelligence

CVE-2026-31941: Chamilo LMS SSRF in Social Wall feature

CVE-2026-31941 · Severity: high · CVSS 7.7 · Published 2026-04-10

Technologies: Chamilo Lms. Vendors: Chamilo.

Executive brief

Chamilo LMS, a popular open-source learning management system, contains a security flaw in its Social Wall feature. An authenticated user, such as a student, can trick the server into making unauthorized requests to internal systems. This could allow an attacker to scan the organization's private network, access sensitive internal services, or steal cloud security credentials, potentially leading to a broader breach of the infrastructure.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in Chamilo LMS prior to versions 1.11.38 and 2.0.0-RC.3. The vulnerability is located in the Social Wall feature's 'read_url_with_open_graph' endpoint, which processes user-supplied URLs via the 'social_wall_new_msg_main' POST parameter. The application fails to validate whether the target URL points to internal or reserved IP addresses before initiating requests via Guzzle and cURL. An authenticated attacker can exploit this to perform internal port scanning, interact with internal services (like Redis or databases), and access cloud metadata services (e.g., 169.254.169.254). The fix introduces URL safety checks that block private IP ranges and restrict protocols to HTTP/HTTPS.

Affected products

  • Chamilo Chamilo LMS < 1.11.38, < 2.0.0-RC.3

Timeline

  • 2026-04-10: advisory: Vendor advisory GHSA-q74c-mx8x-489h published
  • 2026-04-10: disclosed: CVE-2026-31941 published
  • 2026-04-17: patched: NVD analysis and CPE information updated

References