Junglewise Threat Intelligence

CVE-2026-41644: monetr SSRF in Lunch Flow integration

CVE-2026-41644 · Severity: high · CVSS 7.1 · Published 2026-05-07

Technologies: github.com/monetr/monetr (Go). Vendors: Go.

Executive brief

monetr is a budgeting application used to track recurring expenses. A security vulnerability in its Lunch Flow integration allows logged-in users to force the server to make unauthorized requests to internal or external web addresses. This could allow an attacker to scan private internal networks or access sensitive information that is normally protected from the public internet.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the Lunch Flow integration of monetr prior to version 1.12.5. The vulnerability is located in the onboarding and refresh logic, where the application fails to validate user-supplied API URLs before making outbound HTTP GET requests. An authenticated attacker can provide a malicious URL, causing the server to perform requests to internal services or arbitrary external endpoints. Furthermore, the application reflects the response body of non-200 status codes back to the user in API error messages, facilitating data exfiltration or internal service discovery. The fix introduces a configuration-based allowlist for API URLs, defaulting to the official Lunch Flow endpoint.

Affected products

  • monetr monetr < 1.12.5

Timeline

  • 2026-04-17: patched: Fix committed to repository
  • 2026-04-18: advisory: Release v1.12.5 published
  • 2026-05-07: disclosed: CVE published

References

Related threats