Executive brief
Pinry is an open-source image board system that allows users to save and share images and webpages. A flaw in its pin-from-URL feature enables unauthenticated attackers to force the server to make requests to arbitrary internal or external hosts, potentially exposing sensitive internal services or cloud metadata. This could lead to unauthorized access to internal systems or cloud credentials.
Technical details
This is a server-side request forgery (SSRF) vulnerability in Pinry's pin-from-URL feature, which passes user-supplied URLs directly to requests.get() without validating the target host or IP address. The vulnerability is exploitable by unauthenticated attackers because ALLOW_NEW_REGISTRATIONS defaults to true, allowing anonymous users to trigger the vulnerable code path. An attacker can abuse this to reach internal services, cloud metadata endpoints (e.g., AWS IMDSv1), or other restricted hosts accessible from the server. The vulnerability affects Pinry through version 2.1.13; patches or updates to later versions are required to remediate this issue.
Affected products
- Pinry Pinry through 2.1.13
Timeline
- 2026-08-11: disclosed