Junglewise Threat Intelligence

CVE-2026-61520: Simple Machines Forum SSRF in image proxy

CVE-2026-61520 · Severity: high · CVSS 7.7 · Published 2026-07-14

Executive brief

Simple Machines Forum (SMF), a popular open-source community software, contains a security flaw in how it handles images posted by users. An authorized user can trick the forum server into making requests to internal systems that are normally hidden from the public internet. This could allow an attacker to access sensitive internal data, such as cloud server credentials or private internal web applications, potentially leading to a broader breach of the hosting environment.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the image proxy component of Simple Machines Forum (SMF). The vulnerability is rooted in the proxy's failure to validate resolved destination IP addresses against private, loopback, or link-local address ranges when processing BBCode image tags. Authenticated attackers can exploit this by embedding attacker-controlled URLs in posts. Because SMF automatically generates HMAC signatures for embedded image URLs, an attacker can obtain valid signed requests to target internal infrastructure, such as cloud metadata endpoints (IMDS), container network services, or internal web apps. The issue is fixed in version 2.1 via commit 4bf35cf and in version 3.0 via commit b4d23df.

Affected products

  • SimpleMachines SMF (Simple Machines Forum) 2.1 prior to commit 4bf35cf; 3.0 prior to commit b4d23df

Timeline

  • 2026-06-19: patched: Fixes committed to GitHub repository
  • 2026-07-14: disclosed: CVE published and advisory released

References