Junglewise Threat Intelligence

CVE-2026-72591: gabehf Koito server-side request forgery in image endpoint

CVE-2026-72591 · Severity: high · CVSS 7.7 · Published 2026-08-10

Executive brief

Koito is a modern music scrobbler application that tracks listening activity. A flaw in the image upload feature allows an authenticated user to manipulate the server into making HTTP requests to arbitrary internal or external systems, potentially accessing sensitive internal resources or launching attacks against other services on the network.

Technical details

A server-side request forgery (SSRF) vulnerability exists in the PATCH /apis/web/v1/album/{id}/image endpoint in Koito through version 0.3.2. An authenticated attacker can supply a crafted image_url value to force the server to perform HTTP requests to arbitrary hosts. The vulnerability requires authentication to exploit. An attacker can leverage this to access internal services, read metadata from internal systems, or perform reconnaissance against the network infrastructure. A patch is expected to be available in versions after 0.3.2.

Affected products

  • gabehf Koito through 0.3.2

Timeline

  • 2026-08-10: disclosed: CVE-2026-72591 published

References