Executive brief
Friendica is an open-source social networking platform that allows users to create content and interact with other users. A vulnerability in the link-preview feature allows authenticated users to send requests to internal network services and cloud metadata endpoints, potentially exposing sensitive infrastructure information or cloud credentials. An attacker with a free account can map internal networks or access sensitive cloud configuration without proper network restrictions.
Technical details
The vulnerability is a server-side request forgery (SSRF) in Friendica's link-preview endpoint. The endpoint fetches user-supplied URLs without validating against an internal IP deny list, allowing authenticated attackers to probe internal network services and cloud metadata services. The vulnerability requires authentication (a free self-registered account) and network access to the Friendica instance. An attacker can use this to scan internal networks, access private cloud metadata services (such as AWS instance metadata), or enumerate internal services. Patches should implement proper URL validation and maintain an internal IP deny list to restrict requests to private IP ranges and reserved metadata endpoints.
Affected products
- Friendica Friendica through 2026.08-dev
Timeline
- 2026-08-11: disclosed