Executive brief
Koillection is a web-based collection management application that includes a custom scraper feature allowing users to fetch and parse content from URLs. This vulnerability allows any authenticated user to abuse the scraper to access internal network resources (such as metadata services, internal APIs, or databases) that should not be directly accessible to users, potentially exposing sensitive configuration data or internal service information. The impact is especially severe because internal services often lack authentication or rate-limiting when accessed from localhost.
Technical details
The vulnerability is a Server-Side Request Forgery (SSRF) with response disclosure in the scraper endpoints (/scrapers/item-scrapers/scrap, /scrapers/collection-scrapers/scrap, /scrapers/wish-scrapers/scrap). Authenticated users can submit arbitrary target URLs and XPath/path-based extraction rules; the server fetches the target URL without validating whether it points to an internal or private network address. The missing control is the absence of an allowlist/blocklist for target URLs combined with response content being returned to the client after applying user-defined extraction rules. An attacker with authentication credentials can thus enumerate internal HTTP services, extract headers and body content, and potentially interact with internal APIs. The fix, released in version 1.8.4, implements URL validation via a NoPrivateNetworkHttpClient wrapper and a ScrapingUrlGuard component that blocks requests to private network addresses (127.0.0.1, 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16, and other RFC1918 ranges).
Affected products
- Benjamin Jonard Koillection < 1.8.4
Timeline
- 2026-06-15: disclosed: Published to GitHub Advisory Database
- 2026-08-23: patched: Version 1.8.4 released with fix implementing URL validation and private network blocking